[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-134419-en":3,"doc-seo-134419-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},134419,4398048950312,"Violet","https://ap-avatar.wpscdn.com/avatar/400002538284de19e3c?_k=1778320343897328908",8,"Research & Report","Mind the Gap - Detecting Black-box Adversarial Attacks in the Making through Query Update Analysis","Adversarial attacks pose a serious risk to the integrity of machine learning models, and query-based black-box attacks are especially practical because they can craft malicious perturbations without knowing the victim model’s internals. This paper introduces a framework to detect whether adversarial noise generation is underway. Rather than monitoring input-space states, it learns adversarial patterns in an update-similarity space using a new Delta Similarity (DS) metric. Evaluations against eight state-of-the-art attacks, including adaptive evasion attempts, show improved robustness with higher specificity and sensitivity and lower false positives.","This CVPR paper is the Open Access version, provided by the Computer Vision Foundation.  \nExcept for this watermark, it is identical to the accepted version; the final published version of the proceedings is available on IEEE Xplore.  \nMind the Gap: Detecting Black-box Adversarial Attacks in the Making through  \nQuery Update Analysis  \nJeonghwan Park, Niall McLaughlin, Ihsen Alouani  \nQueen’s University Belfast, United Kingdom  \n[jeonghwan.park@uk.thalesgroup.com](jeonghwan.park@uk.thalesgroup.com), {n.mclaughlin, [i.alouani](i.alouani}@qub.ac.uk)[}](i.alouani}@qub.ac.uk)[@qub.ac.uk](i.alouani}@qub.ac.uk)  \nAbstract  \nAdversarial attacks remain a signi􀀂cant threat that can jeopardize the integrity of Machine Learning (ML) models. In particular, query-based black-box attacks can generate malicious noise without having access to the victim model’s architecture, making them practical in real-world contexts. The community has proposed several defenses against adversarial attacks, only to be broken by more advanced and adaptive attack strategies. In this paper, we propose aframework that detects if an adversarial noise instance is being generated. Unlike existing stateful defenses that detect adversarial noise generation by monitoring the input space, our approach learns adversarial patterns in the input update similarity space. Infact, we propose to observe a new metric called Delta Similarity (DS), which we show it captures more ef􀀂ciently the adversarial behavior. We evaluate our approach against 8 state-of-the-art attacks, including adaptive attacks, where the adversary is aware of the defense and tries to evade detection. We 􀀂nd that our approach is signi􀀂cantly more robust than existing defenses both in terms of speci􀀂city and sensitivity.1  \n1. Introduction  \nAdversarial attacks have been investigated as a critical threat to the trustworthiness of ML systems. Two main threat models have been considered in the literature: whitebox and black-box. The white-box setting assumes the adversary has access to the model parameters, architecture and gradient. This setting has been investigated thoroughly to provide a worst-case vulnerability analysis [14, 15, 24] . The second scenario, i.e., black-box, is more practical in real-world contexts and corresponds to an adversary with limited access to the victim model, restricted to inputs and outputs. This threat model is particularly relevant in Machine Learning-as-a-Service (MLaaS) settings, where models can be queried remotely by clients through APIs. A  \n1 Code is available at [https://github.com/jpark04-qub/GWAD](https://github.com/jpark04-qub/GWAD)  \nFigure 1 . A high-level illustration of our intuition. The sequence of malicious queries to generate an adversarial example has a different pattern than benign queries; Attack steps require random vector updates for gradient estimation.  \nmalicious actor generates adversarial perturbations by iteratively querying the model and analyzing the corresponding outputs. Despite the restricted access scenario, many querybased black-box attacks have been proposed [6, 8, 9, 19], showing a high ef􀀂ciency in fooling ML models.  \nMost existing defenses against adversarial attacks frame the problem in a ”post-mortem” manner, i.e., assuming adversarial examples have already been generated [5, 16, 24, 27] . However, a recent line of work speci􀀂cally focused on query-based black-box settings suggests to detect adversarial attacks in the making [7, 10, 23] . These approaches leverage the adversary’s need to query the victim model, proposing to monitor input queries for anomalies in the input space that could indicate attempts to generate adversarial examples. For instance, Stateful Detection [7] identi􀀂es adversarial attack attempts by tracking the similarity (statefulness) between input queries, 􀀃agging anomalous queries that deviate signi􀀂cantly from typical behavior patterns. Similar methods, such as Blacklight [23] and PIHA [10], also rely on statefu","cbCaidlLgSy5x8SV","https://ap.wps.com/l/cbCaidlLgSy5x8SV","pdf",7858032,1,9,"English","en",105,"# Introduction\n## Threat models: white-box vs black-box\n## Query-based black-box attacks and existing defenses\n## Proposed perspective: detect update patterns\n# Delta Similarity and evaluation setup","[{\"question\":\"What problem does the paper address?\",\"answer\":\"It addresses detecting query-based black-box adversarial attacks while the adversarial example is being generated, rather than only after the adversarial example exists.\"},{\"question\":\"How does the proposed method differ from existing defenses?\",\"answer\":\"Existing stateful defenses mainly monitor anomalies in the input space, whereas this work detects adversarial behavior by learning patterns in an input update similarity space using Delta Similarity (DS).\"},{\"question\":\"What metric is introduced and what is its purpose?\",\"answer\":\"The paper introduces Delta Similarity (DS) to capture how updates in a sequence of queries relate over time, providing a more efficient indicator of adversarial behavior.\"}]","Mind the Gap - Detecting Black-box Adversarial Attacks in the Making through Query Update Analysis | PDF",1787259824,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"mind-the-gap-detecting-black-box-adversarial-attacks-in-the-making-through-query-update-analysis","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/mind-the-gap-detecting-black-box-adversarial-attacks-in-the-making-through-query-update-analysis/134419/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-23","2026-08-20",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the paper address?","Question",{"text":76,"@type":77},"It addresses detecting query-based black-box adversarial attacks while the adversarial example is being generated, rather than only after the adversarial example exists.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the proposed method differ from existing defenses?",{"text":81,"@type":77},"Existing stateful defenses mainly monitor anomalies in the input space, whereas this work detects adversarial behavior by learning patterns in an input update similarity space using Delta Similarity (DS).",{"name":83,"@type":74,"acceptedAnswer":84},"What metric is introduced and what is its purpose?",{"text":85,"@type":77},"The paper introduces Delta Similarity (DS) to capture how updates in a sequence of queries relate over time, providing a more efficient indicator of adversarial behavior.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]