[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125535-en":3,"doc-seo-125535-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125535,1099513958607,"Jiven","https://ap-avatar.wpscdn.com/avatar/100002390cf8733938c?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778829742770036399",8,"Research & Report","Preprocessors Matter! Realistic Decision-Based Attacks on Machine Learning Systems","Decision-based adversarial attacks create hard-label inputs that trigger targeted mispredictions in machine learning models. In real deployments, models operate inside larger pipelines, often preceded by preprocessors. Adding a single preprocessor can reduce the effectiveness of state-of-the-art query-based attacks by up to sevenfold compared with attacking the model alone. The gap arises from invariances introduced by preprocessors, which unaware attacks must relearn through many extra queries. The work extracts the preprocessor behavior from a few hundred queries and builds preprocessor-aware, end-to-end attacks that restore near-original efficacy.","Preprocessors Matter! Realistic Decision-Based Attacks on Machine Learning Systems  \nChawin Sitawarin 1 ;2 Florian Tramer2 Nicholas Carlini2  \n1 University of California, Berkeley 2 Google  \narXiv :2210 .03297v 1 [ cs .CR] 7 Oct 2022  \nAbstract—Decision-based adversarial attacks construct inputs that fool a machine learning model into making targeted mispredictions by making only hard-label queries. For the most part, these attacks have been applied directly to isolated neural network models. However, in practice, machine learning models are just a component of a much larger system. By adding just a single preprocessor in front of a classiﬁer, we ﬁnd that state-of-the-art query-based attacks are as much as seven times less effective at attacking a prediction pipeline than attacking the machine learning model alone. We explain this discrepancy by the fact that most preprocessors introduce some notion of invariance to the input space. Hence, attacks that are unaware of this invariance inevitably waste a large number of queries to re-discover or overcome it. We therefore develop techniques to ﬁrst reverseengineer the preprocessor and then use this extracted information to attack the end-to-end system. Our extraction method requires only a few hundreds queries to learn the preprocessors used by most publicly available model pipelines, and our preprocessoraware attacks recover the same efﬁcacy as just attacking the model alone. The code can be found at [https://github.com/](https://github.com/)[ ](https://github.com/)[google-research/preprocessor-aware-black-box-attack](google-research/preprocessor-aware-black-box-attack.)[.](google-research/preprocessor-aware-black-box-attack.)  \nI. INTRODUCTION  \nMachine learning is now widely used to secure systems that might be the target of evasion attacks, with perhaps the most common use being the detection of abusive, harmful or otherwise unsafe content [11, 19, 37] . When used in this way, it is critical that these systems are reliable in the presence of an adversary who seeks to evade them.  \nWorryingly, an extensive body of work has shown that an adversary can generate adversarial examples to fool machine learning models [3, 32] . The majority of these papers focuses on the white-box threat model: where an adversary is assumed to have perfect information about the entire machine learning model [7] . An adversary rarely has this access [34] in practice, and must instead resort to a black-box attack [9] . Recently, there has been a growing body of research under this blackbox threat model. Even given just the model's decision, it is possible to generate imperceptible adversarial examples with decision-based attacks [4] given only thousands of queries.  \nMuch of this black-box line of work often focuses exclusively on fooling stand-alone machine learning models and ignoring any systems built around them. While it is known that machine learning systems can in principle be evaded with adversarial examples—and some black-box attacks have been demonstrated on production systems [17]—it is not yet well understood how these attacks perform on full systems compare to isolated models. In particular, this crucial distinction is rarely discussed by the papers proposing these new attacks.  \nWe show that existing black-box attacks [5, 8, 10, 20] are signiﬁcantly less effective when applied in practical scenarios as opposed to when they are applied directly to an isolated machine learning model. For example, under standard settings, an adversary can employ a decision-based attack to evade a standard ResNet image classiﬁer with an average `2-distortion of 3:7 (deﬁned formally later) . However, if we actually place this classiﬁer as part of a full machine learning system, which has a preprocessor that trivially modiﬁes the input (e.g., by resizing) before classiﬁcation, the required distortion increases by over a factor of seven to 28:5! Even by tuning the hyperparameters or increasing the number of attac","cbCaiadMHyKetaLK","https://ap.wps.com/l/cbCaiadMHyKetaLK","pdf",7802097,1,18,"English","en",105,"# Introduction\n# Background and Related Work\n## Adversarial Examples\n## Black-box Threat Model\n# Preprocessors and Attack Effectiveness\n# Preprocessor-aware Attack Method","[{\"question\":\"Why do decision-based black-box attacks become less effective in full machine learning systems?\",\"answer\":\"Most preprocessors introduce invariance properties in the input space. Decision-based attacks that do not account for these invariances waste queries to rediscover or bypass them.\"},{\"question\":\"What does the paper propose to address the preprocessor problem?\",\"answer\":\"It develops a preprocessor-aware attack that first reverse-engineers the preprocessor using a small number of system queries, then uses that extracted information to attack the end-to-end pipeline.\"},{\"question\":\"How many queries are needed to recover the preprocessors and restore attack efficacy?\",\"answer\":\"The extraction often requires only a few hundred queries to learn preprocessors used by common publicly available model pipelines, after which the attacks recover efficacy comparable to attacking the model alone.\"}]","Preprocessors Matter! Realistic Decision-Based Attacks on Machine Learning Systems | PDF",1785899714,45,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"preprocessors-matter-realistic-decision-based-attacks-on-machine-learning-systems","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/preprocessors-matter-realistic-decision-based-attacks-on-machine-learning-systems/125535/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why do decision-based black-box attacks become less effective in full machine learning systems?","Question",{"text":75,"@type":76},"Most preprocessors introduce invariance properties in the input space. Decision-based attacks that do not account for these invariances waste queries to rediscover or bypass them.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What does the paper propose to address the preprocessor problem?",{"text":80,"@type":76},"It develops a preprocessor-aware attack that first reverse-engineers the preprocessor using a small number of system queries, then uses that extracted information to attack the end-to-end pipeline.",{"name":82,"@type":73,"acceptedAnswer":83},"How many queries are needed to recover the preprocessors and restore attack efficacy?",{"text":84,"@type":76},"The extraction often requires only a few hundred queries to learn preprocessors used by common publicly available model pipelines, after which the attacks recover efficacy comparable to attacking the model alone.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]