An attack that involves finding key features that can be subtly altered to affect classification.