Joana Cabral Costa, Tiago Roxo, Hugo Proença, Pedro R. M. Inácio · Image and Vision Computing 2026 · 2026
DOI: 10.1016/j.imavis.2026.106228
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Current black-box adversarial attacks either require multiple queries or diffusion models to produce adversarial samples that can impair the target model performance. However, these methods have limited applicability in real-world settings, where the attacker does not have unlimited time to interact with the target model. The Zero-Query Black-box Adversarial (ZQBA) attack introduces a feature-map-based strategy that allows adversarial examples to be pre-computed during an offline setup phase and later deployed in time-constrained environments, benefiting from high transferability across architectures and domains. Building upon ZQBA, this paper proposes using feature-aware perturbations from ZQBA complemented with Adversarial Training (AT) to improve the robustness across diverse attack scenarios. Our results show that incorporating ZQBA perturbations into AT improves robustness on white-box, black-box and transfer-based settings, suggesting that these perturbations provide complementary regularization effects that reduce sensitivity to small input variations. Overall, our findings highlight the potential of feature-aware perturbations as an efficient and query-free component for strengthening model robustness. All the source code is available at https://github.com/Joana-Cabral/ZQBA .
No comments yet — start the discussion below.