OASIS: Optimizing Attacker Sequences for Hard-Label Black-Box Text Attacks
Experiments across multiple datasets, victim models, and large language models show that OASIS consistently outperforms strong standalone baselines and simple manually constructed chains, suggesting that attacker composition is not merely an implementation choice, but a practical optimization target for improving hard-label black-box text attacks.