arXiv · 2609.25734
GuidedRay: Diversity-Guided Direction Discovery for Targeted Hard-Label Black-Box Attacks
Abstract
Deep neural networks are vulnerable to adversarial attacks. Among black-box attacks, targeted decision-based attacks are particularly difficult: the attacker observes only the target model's top-1 label and aims to make it predict a prespecified target class under a bounded perturbation. Before perturbation refinement, the attacker must discover a direction that reaches the prescribed target region. This initialization step can incur substantial query cost. We propose GuidedRay, a targeted decision-based attack based on diversity-guided direction discovery. GuidedRay builds on two observations: target-class reference samples provide useful target-conditioned direction priors, and diverse candidates increase the probability of discovering a targeted adversarial direction. GuidedRay generates varied candidates from one or multiple target-class references and uses a one-query Fast Test to screen their induced sign directions. Once a feasible direction is found, GuidedRay applies Ray Search to reduce its decision-boundary radius. Experiments on CIFAR-10, CIFAR-100, and ImageNet demonstrate that GuidedRay consistently outperforms five state-of-the-art decision-based attacks at four evaluated query budgets from 500 to 5,000, with particularly pronounced gains in direction discovery during initialization. Against models protected by adversarial training or TRADES, it likewise achieves the highest attack success rate at all four query budgets.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Fei Yuan, Yantian Shen, Qingyuan Yu, Yi Chen, Binghui Wang, Hongbo Yu, Anyu Wang, Xiaoyun Wang. 2026-09-22. GuidedRay: Diversity-Guided Direction Discovery for Targeted Hard-Label Black-Box Attacks. https://arxiv.org/abs/2609.25734
Cite the original work for its findings. Save a collection to share your selection of sources.