Back to papers
arxiv6.0 / 10

OASIS: Optimizing Attacker Sequences for Hard-Label Black-Box Text Attacks

Qian Chen, Shiliang Xiao, Yuzhi Liang

Abstract

Different attack methods follow different search trajectories, they succeed on different subsets of samples, whereas existing hard-label black-box text attacks mainly focus on improving individual attackers or manually combining them. We present {\OURS}, a method for optimizing attacker sequences in hard-label black-box text attacks. {\OURS} first performs a one-time bi-objective attack chain search over candidate sequences to balance attack success rate and perturbation, and then reuses the selected fixed global chain during attack chain execution. Experiments across multiple datasets, victim models, and large language models show that {\OURS} consistently outperforms strong standalone baselines and simple manually constructed chains. These results suggest that attacker composition is not merely an implementation choice, but a practical optimization target for improving hard-label black-box text attacks.

Research area

ai securityred-teamingsecurity
Published
30 Aug 2026
Source
arxiv
Org
Guangdong University of Foreign Studies
View paper
Sign in to read and join the discussion.