Black-box Adversarial Attacks with Limited Queries and Information

Andrew IlyasLogan EngstromAnish AthalyeJessy Lin

article2018ICML1,415 citations

Develops practical black-box adversarial attack methods that fool image classifiers under strict query and feedback constraints, proving their real-world threat by successfully deceiving the Google Cloud Vision API.

Listen

Commercial and proprietary artificial intelligence systems frequently rely on "black-box" security assumptions, where internal model parameters, training data, and gradients remain hidden from users. However, standard black-box attack evaluations assume an adversary can make infinite queries and receive complete probability distributions over all possible classes. In commercial applications, systems impose query limits, introduce monetary costs per query, restrict output to partial scores, or provide only sorted class labels without confidence metrics. Understanding whether neural networks remain vulnerable under these strict operational constraints is critical for assessing the actual security of deployed machine learning systems.

The article demonstrates that targeted adversarial attacks remain highly effective even under realistic real-world restrictions. It introduces new algorithms designed to fool classifiers across three constrained threat models: query-limited, partial-information, and label-only settings.

To evaluate vulnerability without internal model access, the authors adapted Natural Evolution Strategies (NES) to estimate gradients using derivative-free optimization over random Gaussian noise. For partial-information settings, the authors developed an optimization algorithm that begins with an image of the target class and alternates between projected gradient descent to maximize target confidence and backtracking line searches to blend in the source image. For label-only settings, where classifiers provide no probability scores, the method uses random local noise perturbations to calculate a proxy score based on how consistently the label appears. These techniques were systematically tested on the standard InceptionV3 image classification benchmark using 1,000 test images (100 for label-only tests) and validated on a live commercial platform, the Google Cloud Vision API.

The experimental findings show that restrictive interfaces fail to prevent targeted adversarial manipulation. In the query-limited setting, the attack achieved a 99.2% targeted success rate with a median of 11,550 queries—reducing the query cost by two to three orders of magnitude compared to prior gradient estimation approaches. In the partial-information setting where only top-1 probabilities are exposed, the attack achieved a 93.6% success rate requiring a median of 49,624 queries. In the label-only setting where no scores are returned, the attack reached a 90.0% success rate with a median of 2.7 million queries. Finally, the authors successfully executed a targeted attack against the Google Cloud Vision API, converting an image of skiers into an adversarial image that appeared visually unchanged to humans but was classified by the API as a dog.

These results demonstrate that commercial machine learning models are vulnerable to targeted manipulation despite strict output filtering, paywalls, or rate-limiting. Limiting output feedback does increase the query budget required for an attack, but it does not provide security against determined adversaries. Security and risk teams should not rely on black-box opacity or simple output stripping as a sufficient defense, and future defensive strategies must focus on model robustness rather than superficial interface restrictions. While the empirical results firmly establish this vulnerability across both benchmark models and commercial APIs, decision-makers should note that the label-only setting requires substantial query volumes that may be detectable under strict traffic monitoring or rate limiting.

Cover for Black-box Adversarial Attacks with Limited Queries and Information

Abstract

Current neural network-based classifiers are susceptible to adversarial examples even in the black-box setting, where the attacker only has query access to the model. In practice, the threat model for real-world systems is often more restrictive than the typical black-box model where the adversary can observe the full output of the network on arbitrarily many chosen inputs. We define three realistic threat models that more accurately characterize many real-world classifiers: the query-limited setting, the partial-information setting, and the label-only setting. We develop new attacks that fool classifiers under these more restrictive threat models, where previous methods would be impractical or ineffective. We demonstrate that our methods are effective against an ImageNet classifier under our proposed threat models. We also demonstrate a targeted black-box attack against a commercial classifier, overcoming the challenges of limited query access, partial information, and other practical issues to break the Google Cloud Vision API.

Table of Contents

  • 1 Introduction
  • 1.1 Definitions
  • 1.2 Contributions
  • 2 Approach
  • 2.1 Query-Limited Setting
  • 2.1.1 Natural Evolutionary Strategies
  • 2.1.2 Query-Limited Attack
  • 2.2 Partial-Information Setting
  • 2.3 Label-Only Setting
  • 3 Evaluation
  • 3.1 Methodology
  • 3.2 Evaluation on ImageNet
  • 3.3 Real-world attack on Google Cloud Vision
  • 4 Related work
  • 4.1 Black-box adversarial attacks
  • 4.1.1 Black-box attacks with substitute networks
  • 4.1.2 Black-box attacks with gradient estimation
  • 4.2 Adversarial attacks with limited information
  • 4.3 Other adversarial attacks
  • 5 Conclusion
  • References

Knowls

  1. Knowl 1 — Natural Evolutionary Strategies Gradient Estimation for Black-Box Adversarial Attacks

    algorithm

    In the query-limited black-box setting, an adversary cannot compute analytical gradients via backpropagation. Instead, the gradient ∇xEθ∼π(⋅∣x)[F(θ)]\nabla_x \mathbb{E}_{\theta \sim \pi(\cdot|x)}[F(\theta)] of a loss function FF under a search distribution π(θ∣x)=N(x,σ2I)\pi(\theta|x) = \mathcal{N}(x, \sigma^2 I) is estimated using Natural Evolutionary Strategies (NES) with antithetic Gaussian sampling:

    ∇xE[F(θ)]≈12nσ∑i=1n(F(x+σui)−F(x−σui))ui\nabla_x \mathbb{E}[F(\theta)] \approx \frac{1}{2n\sigma} \sum_{i=1}^n \left( F(x + \sigma u_i) - F(x - \sigma u_i) \right) u_i

    where ui∼N(0,IN)u_i \sim \mathcal{N}(0, I_N) are random Gaussian vectors. This gradient estimate is used in projected gradient descent (PGD) with step size η\eta and momentum to iteratively update the adversarial image x(t)x^{(t)} within an ℓ∞\ell_\infty ball of radius ϵ\epsilon centered at original image x0x_0:

    x(t)=Π[x0−ϵ,x0+ϵ](x(t−1)−η⋅sign(gt))x^{(t)} = \Pi_{[x_0 - \epsilon, x_0 + \epsilon]}\left(x^{(t-1)} - \eta \cdot \text{sign}(g_t)\right)

    Input: Classifier probability function P(y∣x)P(y|x) for target class yy, current image xx
    Output: Estimated gradient g≈∇xP(y∣x)g \approx \nabla_x P(y|x)
    Parameters: Search variance σ\sigma, sample count nn, image dimensionality NN
    g←0Ng \leftarrow 0_N
    for i=1i = 1 to nn do
      ui∼N(0N,IN)u_i \sim \mathcal{N}(0_N, I_N)
      g←g+P(y∣x+σ⋅ui)⋅uig \leftarrow g + P(y|x + \sigma \cdot u_i) \cdot u_i
      g←g−P(y∣x−σ⋅ui)⋅uig \leftarrow g - P(y|x - \sigma \cdot u_i) \cdot u_i
    end for
    return 12nσg\frac{1}{2n\sigma} g
  2. Knowl 2 — Partial-Information Targeted Adversarial Attack Algorithm

    algorithm

    When an adversary only observes probabilities or confidence scores for the top-kk classes, an attack initialized from the original source image xx cannot obtain gradient information for the target class yadvy_{\text{adv}} if yadvy_{\text{adv}} is outside the top-kk. The partial-information attack resolves this by starting from an image x0x_0 that already belongs to the target class yadvy_{\text{adv}} (where it is in the top-kk), and alternating between shrinking an ℓ∞\ell_\infty bounding box toward the source image xx and maximizing the probability of yadvy_{\text{adv}} via NES gradient ascent.

    Input: Initial target image x0x_0, original image xx, target class yadvy_{\text{adv}}, classifier P(y∣x)P(y|x)
    Output: Adversarial image xadvx_{\text{adv}} satisfying ∥xadv−x∥∞≤ϵadv\|x_{\text{adv}} - x\|_\infty \le \epsilon_{\text{adv}}
    Parameters: Target bound ϵadv\epsilon_{\text{adv}}, initial perturbation ϵ0\epsilon_0, NES parameters (σ,N,n)(\sigma, N, n), decay δϵ\delta_\epsilon, learning rate range [ηmin,ηmax][\eta_{\text{min}}, \eta_{\text{max}}]
    ϵ←ϵ0\epsilon \leftarrow \epsilon_0
    xadv←x0x_{\text{adv}} \leftarrow x_0
    xadv←CLIP(xadv,x−ϵ,x+ϵ)x_{\text{adv}} \leftarrow \text{CLIP}(x_{\text{adv}}, x - \epsilon, x + \epsilon)
    while ϵ>ϵadv\epsilon > \epsilon_{\text{adv}} or arg⁡max⁡yP(y∣xadv)≠yadv\arg\max_y P(y|x_{\text{adv}}) \ne y_{\text{adv}} do
      g←NESESTGRAD(P(yadv∣xadv))g \leftarrow \text{NESESTGRAD}(P(y_{\text{adv}}|x_{\text{adv}}))
      η←ηmax\eta \leftarrow \eta_{\text{max}}
      x^adv←xadv−ηg\hat{x}_{\text{adv}} \leftarrow x_{\text{adv}} - \eta g
      while not yadv∈TOP-K(P(⋅∣x^adv))y_{\text{adv}} \in \text{TOP-K}(P(\cdot|\hat{x}_{\text{adv}})) do
        if η<ηmin\eta < \eta_{\text{min}} then
          ϵ←ϵ+δϵ\epsilon \leftarrow \epsilon + \delta_\epsilon
          δϵ←δϵ/2\delta_\epsilon \leftarrow \delta_\epsilon / 2
          x^adv←xadv\hat{x}_{\text{adv}} \leftarrow x_{\text{adv}}
          break
        end if
        η←η/2\eta \leftarrow \eta / 2
        x^adv←CLIP(xadv−ηg,x−ϵ,x+ϵ)\hat{x}_{\text{adv}} \leftarrow \text{CLIP}(x_{\text{adv}} - \eta g, x - \epsilon, x + \epsilon)
      end while
      xadv←x^advx_{\text{adv}} \leftarrow \hat{x}_{\text{adv}}
      ϵ←ϵ−δϵ\epsilon \leftarrow \epsilon - \delta_\epsilon
    end while
    return xadvx_{\text{adv}}
  3. Knowl 3 — Noise Robustness Score Proxy for Label-Only Adversarial Attacks

    model/method

    In the label-only threat model, the classifier returns only an ordered list of the top-kk inferred class labels without probabilities or continuous confidence scores. To generate a continuous surrogate function for optimization, the attack defines a discretized rank score:

    R(x(t))=k−rank(yadv∣x(t))R(x^{(t)}) = k - \text{rank}(y_{\text{adv}} | x^{(t)})

    where rank(yadv∣x)\text{rank}(y_{\text{adv}}|x) is the 1-indexed position of label yadvy_{\text{adv}} in the predicted top-kk list. If yadvy_{\text{adv}} is outside the top-kk, R(x(t))≤0R(x^{(t)}) \le 0.

    A continuous proxy score S(x(t))S(x^{(t)}) is constructed by evaluating the robustness of RR under random uniform noise drawn from an ℓ∞\ell_\infty ball of radius μ\mu:

    S(x(t))=Eδ∼U[−μ,μ][R(x(t)+δ)]S(x^{(t)}) = \mathbb{E}_{\delta \sim \mathcal{U}[-\mu, \mu]}\left[ R(x^{(t)} + \delta) \right]

    This expected value is estimated via Monte Carlo sampling with mm noise perturbations:

    S^(x(t))=1m∑i=1mR(x(t)+μδi),δi∼U[−1,1]N\widehat{S}(x^{(t)}) = \frac{1}{m} \sum_{i=1}^m R(x^{(t)} + \mu \delta_i), \quad \delta_i \sim \mathcal{U}[-1, 1]^N

    The proxy score S^(x)\widehat{S}(x) replaces the probability output P(yadv∣x)P(y_{\text{adv}}|x) in the partial-information attack framework, allowing derivative-free gradient estimation ∇xS^(x)\nabla_x \widehat{S}(x) via NES.

  4. Knowl 4 — Restricted Black-Box Threat Models: Query-Limited, Partial-Information, and Label-Only

    definition

    Adversarial attacks under black-box settings are categorized into three threat models that impose realistic constraints beyond standard black-box query access:

    1. Query-limited setting: The adversary can query any image xx and receive full predicted class probabilities P(y∣x)P(y|x) for all classes yy, but must produce a targeted adversarial example within a strict query budget LL.
    2. Partial-information setting: The adversary only receives output probabilities or unnormalized confidence scores for the top-kk predicted classes {y1,…,yk}\{y_1, \dots, y_k\} (where k≥1k \ge 1). In the extreme case k=1k=1, the adversary only sees the top-1 label and its associated score.
    3. Label-only setting: The adversary receives an ordered list of the top-kk inferred labels without any numerical scores or probabilities (generalizing decision-only attacks where k=1k=1).
  5. Knowl 5 — Performance of Targeted Black-Box Attacks on ImageNet

    data/table

    The effectiveness of the query-limited (QL), partial-information (PI, k=1k=1), and label-only (LO, k=1k=1) attacks was evaluated on an InceptionV3 classifier (78%78\% top-1 accuracy) using 1000 randomly selected ImageNet test images (100 for LO) with randomly selected target classes under an ℓ∞\ell_\infty perturbation budget of ϵ=0.05\epsilon = 0.05.

    Threat Model Success Rate Median Queries
    Query-Limited (QL) 99.2% 11,550
    Partial-Information (PI, k=1k=1) 93.6% 49,624
    Label-Only (LO, k=1k=1) 90.0% 2.7×1062.7 \times 10^6

    Hyperparameters used across all test images:

    • General NES parameters: search variance σ=0.001\sigma = 0.001, population size n=50n = 50, learning rate η=0.01\eta = 0.01.
    • Partial-information parameters: initial perturbation distance ϵ0=0.5\epsilon_0 = 0.5, decay rate δϵ=0.001\delta_\epsilon = 0.001.
    • Label-only parameters: proxy score Monte Carlo sample count m=50m = 50, sampling ball ℓ∞\ell_\infty radius μ=0.001\mu = 0.001.
  6. Knowl 6 — Targeted Adversarial Attack on Google Cloud Vision API

    empirical result

    The partial-information attack successfully executed a targeted adversarial attack against the commercial Google Cloud Vision (GCV) object labeling API. GCV presents severe black-box restrictions:

    1. The label set is opaque and non-enumerated (consisting of thousands of classes).
    2. Confidence scores are neither normalized probabilities nor logits.
    3. Returned label lists vary in length between queries (up to 10 classes).

    By initializing the attack with an image of the target class ("dog") and iteratively projecting toward an unperturbed image of skiers (originally classified as "skiing" and "ski"), the algorithm synthesized an adversarial image that appeared visually identical to the skiers within an ℓ∞\ell_\infty bound of ϵ=0.1\epsilon = 0.1, while GCV classified it with top confidence as "dog" and "dog like mammal".

  7. Knowl 7 — Norm Concentration Bound for Gaussian-Projected NES Gradient Estimation

    theoretical result

    Let ∇F\nabla F denote the true gradient of an objective function FF, and let ∇F^\widehat{\nabla F} denote the NES gradient estimate computed over NN Gaussian random vectors. By viewing the NES estimation as a random Gaussian projection and applying the Johnson-Lindenstrauss Theorem, in the limit as search variance σ→0\sigma \to 0, the norm of the estimated gradient ∇F^\widehat{\nabla F} concentrates around the true gradient norm ∥∇F∥\|\nabla F\|:

    P((1−δ)∥∇F∥2≤∥∇F^∥2≤(1+δ)∥∇F∥2)≥1−2p\mathbb{P}\left( (1 - \delta)\|\nabla F\|^2 \le \|\widehat{\nabla F}\|^2 \le (1 + \delta)\|\nabla F\|^2 \right) \ge 1 - 2p

    where 0<δ<10 < \delta < 1 and the required sample size satisfies N=O(−δ−2log⁡p)N = O(-\delta^{-2} \log p).

Coverage note — None was omitted; all primary threat model definitions, algorithms (NES PGD, partial-information, label-only noise robustness proxy), theoretical bounds, ImageNet quantitative evaluations, and real-world GCV API attack results are included.

References

  1. 1.Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K. Synthesizing robust adversarial examples. 2017. URL https://arxiv.org/abs/1707.07397.
  2. 2.Biggio, B., Nelson, B., and Laskov, P. Poisoning attacks against support vector machines. In Proceedings of the 29th International Coference on International Conference on Machine Learning, ICML’12, pp. 1467–1474, 2012. ISBN 978-1-4503-1285-1. URL http://dl.acm.org/citation.cfm?id=3042573.3042761.
  3. 3.Biggio, B., Corona, I., Maiorca, D., Nelson, B., Srndīć, N., Laskov, P., Giacinto, G., and Roli, F. Evasion attacks against machine learning at test time. In Joint European Conference on Machine Learning and Knowledge Discovery in Databases, pp. 387–402. Springer, 2013.
  4. 4.Brendel, W., Rauber, J., and Bethge, M. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In Proceedings of the International Conference on Learning Representations (ICLR), 2018. URL https://arxiv.org/abs/1712.04248.
  5. 5.Carlini, N. and Wagner, D. Towards evaluating the robustness of neural networks. In IEEE Symposium on Security & Privacy, 2017.
  6. 6.Carlini, N., Mishra, P., Vaidya, T., Zhang, Y., Sherr, M., Shields, C., Wagner, D., and Zhou, W. Hidden voice commands. In 25th USENIX Security Symposium (USENIX Security 16), Austin, TX, 2016.
  7. 7.Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.-J. Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, AISec ’17, pp. 15–26, New York, NY, USA, 2017. ACM. ISBN 978-1-4503-5202-4. doi: 10.1145/3128572.3140448. URL http://doi.acm.org/10.1145/3128572.3140448.
  8. 8.Dasgupta, S., Hsu, D., and Verma, N. A concentration theorem for projections. In Conference on Uncertainty in Artificial Intelligence, 2006.
  9. 9.Evtimov, I., Eykholt, K., Fernandes, E., Kohno, T., Li, B., Prakash, A., Rahmati, A., and Song, D. Robust physical-world attacks on machine learning models. CoRR, abs/1707.08945, 2017.
  10. 10.Goodfellow, I. J., Shlens, J., and Szegedy, C. Explaining and harnessing adversarial examples. In Proceedings of the International Conference on Learning Representations (ICLR), 2015.
  11. 11.Gorban, A. N., Tyukin, I. Y., Prokhorov, D. V., and Sofeikov, K. I. Approximation with random bases. Inf. Sci., 364(C): 129–145, October 2016. ISSN 0020-0255. doi: 10.1016/j.ins.2015.09.021. URL http://dx.doi.org/10.1016/j.ins.2015.09.021.
  12. 12.Hayes, J. and Danezis, G. Machine learning as an adversarial service: Learning black-box adversarial examples. CoRR, abs/1708.05207, 2017.
  13. 13.Hosseini, H., Xiao, B., Jaiswal, M., and Poovendran, R. On the limitation of convolutional neural networks in recognizing negative images. 2017 16th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 352–358, 2017.
  14. 14.Hu, W. and Tan, Y. Black-box attacks against RNN based malware detection algorithms. CoRR, abs/1705.08131, 2017.
  15. 15.Kurakin, A., Goodfellow, I., and Bengio, S. Adversarial examples in the physical world. 2016. URL https://arxiv.org/abs/1607.02533.
  16. 16.Liu, Y., Chen, X., Liu, C., and Song, D. Delving into transferable adversarial examples and black-box attacks. In Proceedings of the International Conference on Learning Representations (ICLR), 2017.
  17. 17.Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. Towards deep learning models resistant to adversarial attacks. 2017. URL https://arxiv.org/abs/1706.06083.
  18. 18.Moosavi-Dezfooli, S., Fawzi, A., Fawzi, O., and Frossard, P. Universal adversarial perturbations. In CVPR, pp. 86–94. IEEE Computer Society, 2017.
  19. 19.Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P. Deepfool: a simple and accurate method to fool deep neural networks. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2016.
  20. 20.Narodytska, N. and Kasiviswanathan, S. P. Simple black-box adversarial perturbations for deep networks. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2017.
  21. 21.Nesterov, Y. and Spokoiny, V. Random gradient-free minimization of convex functions. Found. Comput. Math., 17(2):527–566, April 2017. ISSN 1615-3375. doi: 10.1007/s10208-015-9296-2. URL https://doi.org/10.1007/s10208-015-9296-2.
  22. 22.Nguyen, A. M., Yosinski, J., and Clune, J. Deep neural networks are easily fooled: High confidence predictions for unrecognizable images. CoRR, abs/1412.1897, 2014.
  23. 23.Papernot, N., McDaniel, P., and Goodfellow, I. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. 2016a.
  24. 24.Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A. The limitations of deep learning in adversarial settings. In IEEE European Symposium on Security & Privacy, 2016b.
  25. 25.Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A. Practical black-box attacks against machine learning. In Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS ’17, pp. 506–519, New York, NY, USA, 2017. ACM. ISBN 978-1-4503-4944-4. doi: 10.1145/3052973.3053009. URL http://doi.acm.org/10.1145/3052973.3053009.
  26. 26.Salimans, T., Ho, J., Chen, X., and Sutskever, I. Evolution strategies as a scalable alternative to reinforcement learning. CoRR, abs/1703.03864, 2017. URL http://arxiv.org/abs/1703.03864.
  27. 27.Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M. K. Adversarial generative nets: Neural network attacks on state-of-the-art face recognition. 2017.
  28. 28.Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. Intriguing properties of neural networks. 2013. URL https://arxiv.org/abs/1312.6199.
  29. 29.Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z. Rethinking the inception architecture for computer vision. 2015. URL https://arxiv.org/abs/1512.00567.
  30. 30.Wierstra, D., Schaul, T., Glasmachers, T., Sun, Y., Peters, J., and Schmidhuber, J. Natural evolution strategies. J. Mach. Learn. Res., 15(1):949–980, January 2014. ISSN 1532-4435. URL http://dl.acm.org/citation.cfm?id=2627435.2638566.
  31. 31.Xu, W., Yi, Y., and Evans, D. Automatically evading classifiers: A case study on pdf malware classifiers. Network and Distributed System Security Symposium (NDSS), 2016.

Citation

MLA
Ilyas, A., et al. “Black-box Adversarial Attacks with Limited Queries and Information”. arXiv, 2018, http://arxiv.org/abs/1804.08598v3.
APA
Ilyas, A., Engstrom, L., Athalye, A., & Lin, J. (2018). Black-box Adversarial Attacks with Limited Queries and Information. arXiv. http://arxiv.org/abs/1804.08598v3
Chicago
Ilyas, A., L. Engstrom, A. Athalye, and J. Lin. 2018. “Black-box Adversarial Attacks with Limited Queries and Information”. arXiv. http://arxiv.org/abs/1804.08598v3.
Harvard
Ilyas, A. et al. (2018) “Black-box Adversarial Attacks with Limited Queries and Information”, arXiv [Preprint]. Available at: http://arxiv.org/abs/1804.08598v3.
Vancouver
1. Ilyas A, Engstrom L, Athalye A, Lin J (2018) Black-box Adversarial Attacks with Limited Queries and Information. arXiv

BibTeX

@article{ilyas2018black,
  title = {Black-box Adversarial Attacks with Limited Queries and Information},
  author = {Ilyas, Andrew and Engstrom, Logan and Athalye, Anish and Lin, Jessy},
  year = {2018},
  journal = {arXiv},
  url = {http://arxiv.org/abs/1804.08598v3},
  eprint = {1804.08598}
}
Metadata:arXiv

Source Code

This paper has an official code repository available. Click below to access the source code.

View Repository

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: https://creativecommons.org/licenses/by/4.0/