Discovering Natural Transformation Vulnerabilities in Black-Box Vision Models
Quick summary
arXiv:2609.07110v1 Announce Type: cross Abstract: Natural adversarial examples (NAEs) reveal that vision models can fail under realistic semantic changes beyond norm-bounded perturbations. However, generating NAEs in a black-box setting remains challenging because existing generative attacks often rely on surrogate models, learned attack priors, or costly query-based optimization, whereas the natural transformations that expose model vulnerabilities are unknown a priori. We propose \textbf{Adversarial Scenario Attack (ASA)}, a query-based black-box framework that searches over natural-language
Key takeaways
- arXiv:2609.07110v1 Announce Type: cross Abstract: Natural adversarial examples (NAEs) reveal that vision models can fail under realistic semantic changes beyond norm-bounded perturbations.
- However, generating NAEs in a black-box setting remains challenging because existing generative attacks often rely on surrogate models, learned attack priors, or costly query-based optimization, whereas the natural transformations that expose model vulnerabilities are unknown a priori.
- We propose \textbf{Adversarial Scenario Attack (ASA)}, a query-based black-box framework that searches over natural-language
Why it matters
“Discovering Natural Transformation Vulnerabilities in Black-Box Vision Models” should be evaluated beyond branding and benchmark scores. Its practical importance will emerge in task accuracy, latency, unit cost, safety and integration with real workflows.

Member comments