Fetching the paper…
Reading the bibliography…
Transferable adversarial images raise critical security concerns for computer vision systems in real-world, black-box attack scenarios.
Some methods of speeding up the convergence of iteration methods
Boris T Polyak · 1964
Earlier work this paper cites.
A method of solving a convex programming problem with convergence rate o(1/kˆ2)
Yurii Evgen’evich Nesterov · 1983
Earlier work this paper cites.
The development of the CIE 2000 colour-difference formula: CIEDE2000
Ming Ronnier Luo, Guihua Cui, and B. Rigg · 2001
Earlier work this paper cites.
Image quality assessment: from error visibility to structural similarity
Zhou Wang, Alan C. Bovik, Hamid R. Sheikh, and Eero P. Simoncelli · 2004
Earlier work this paper cites.
Generative adversarial nets
Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
How transferable are features in deep neural networks?
Jason Yosinski, Jeff Clune, Yoshua Bengio, and Hod Lipson · 2014
Earlier work this paper cites.
Visualizing and understanding convolutional networks
Matthew D Zeiler and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami · 2016
Earlier work this paper cites.
Adversarial diversity and hard positive generation
Andras Rozsa, Ethan M Rudd, and Terrance E Boult · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna · 2016
Earlier work this paper cites.
Learning deep features for discriminative localization
Bolei Zhou, Aditya Khosla, Agata Lapedriza, Aude Oliva, and Antonio Torralba · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Densely connected convolutional networks
Gao Huang, Zhuang Liu, Laurens Van Der Maaten, and Kilian Q Weinberger · 2017
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Earlier work this paper cites.
Grad-cam: Visual explanations from deep networks via gradient-based localization
Ramprasaath R Selvaraju, Michael Cogswell, Abhishek Das, Ramakrishna Vedantam, Devi Parikh, and Dhruv Batra · 2017
Earlier work this paper cites.
Axiomatic attribution for deep networks
Mukund Sundararajan, Ankur Taly, and Qiqi Yan · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli · 2018
Earlier work this paper cites.
Grad-CAM++: Generalized gradient-based visual explanations for deep convolutional networks
A. Chattopadhay, A. Sarkar, P. Howlader, and V. N. Balasubramanian · 2018
Earlier work this paper cites.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Earlier work this paper cites.
Geometric robustness of deep networks: analysis and improvement
Can Kanbak, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2018
Earlier work this paper cites.
Defense against adversarial attacks using high-level representation guided denoiser
Fangzhou Liao, Ming Liang, Yinpeng Dong, Tianyu Pang, Xiaolin Hu, and Jun Zhu · 2018
Earlier work this paper cites.
Towards imperceptible and robust adversarial example attacks against neural networks
Bo Luo, Yannan Liu, Lingxiao Wei, and Qiang Xu · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Task-generalizable adversarial attack based on perceptual metric
Muzammal Naseer, Salman H Khan, Shafin Rahman, and Fatih Porikli · 2018
Earlier work this paper cites.
Generative adversarial perturbations
Omid Poursaeed, Isay Katsman, Bicheng Gao, and Serge Belongie · 2018
Earlier work this paper cites.
Deflecting adversarial attacks with pixel deflection
Aaditya Prakash, Nick Moran, Solomon Garber, Antonella DiLillo, and James Storer · 2018
Earlier work this paper cites.
On the suitability of L p L_{p} -norms for creating and preventing adversarial examples
Mahmood Sharif, Lujo Bauer, and Michael K. Reiter · 2018
Earlier work this paper cites.
Spatially transformed adversarial examples
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song · 2018
Earlier work this paper cites.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille · 2018
Earlier work this paper cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2018
Earlier work this paper cites.
The unreasonable effectiveness of deep features as a perceptual metric
Richard Zhang, Phillip Isola, Alexei A Efros, Eli Shechtman, and Oliver Wang · 2018
Earlier work this paper cites.
Transferable adversarial perturbations
Wen Zhou, Xin Hou, Yongjun Chen, Mengyun Tang, Xiangqi Huang, Xiang Gan, and Yong Yang · 2018
Cited alongside, same era.
ADef: an iterative algorithm to construct adversarial deformations
Rima Alaifari, Giovanni S Alberti, and Tandri Gauksson · 2019
Cited alongside, same era.
On evaluating adversarial robustness
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin · 2019
Cited alongside, same era.
Sparse and imperceivable adversarial attacks
Francesco Croce and Matthias Hein · 2019
Cited alongside, same era.
Evading defenses to transferable adversarial examples by translation-invariant attacks
Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu · 2019
Cited alongside, same era.
FDA: Feature disruptive attack
Aditya Ganeshan, Vivek BS, and R Venkatesh Babu · 2019
Cited alongside, same era.
An image is worth 16x16 words: Transformers for image recognition at scale
Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, et al · 2021
Later among the works it cites.
Learning transferable adversarial perturbations
Krishna kanth Nakka and Mathieu Salzmann · 2021
Later among the works it cites.
Perceptual adversarial robustness: Defense against unseen threat models
Cassidy Laidlaw, Sahil Singla, and Soheil Feizi · 2021
Later among the works it cites.
Uncovering the connections between adversarial transferability and knowledge transferability
Kaizhao Liang, Jacky Y Zhang, Boxin Wang, Zhuolin Yang, Sanmi Koyejo, and Bo Li · 2021
Later among the works it cites.
On generating transferable targeted perturbations
Muzammal Naseer, Salman Khan, Munawar Hayat, Fahad Shahbaz Khan, and Fatih Porikli · 2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Enhancing adversarial example transferability with an intermediate level attack
Qian Huang, Isay Katsman, Horace He, Zeqi Gu, Serge Belongie, and Ser-Nam Lim · 2019
Cited alongside, same era.
Adversarial examples are not bugs, they are features
Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry · 2019
Cited alongside, same era.
Feature space perturbations yield more transferable adversarial examples
Nathan Inkawhich, Wei Wen, Hai Helen Li, and Yiran Chen · 2019
Cited alongside, same era.
Similarity of neural network representations revisited
Simon Kornblith, Mohammad Norouzi, Honglak Lee, and Geoffrey Hinton · 2019
Cited alongside, same era.
Who’s afraid of adversarial queries? the impact of image modifications on content-based image retrieval
Zhuoran Liu, Zhengyu Zhao, and Martha Larson · 2019
Cited alongside, same era.
Cross-domain transferability of adversarial perturbations
Muzammal Naseer, Salman H Khan, Harris Khan, Fahad Shahbaz Khan, and Fatih Porikli · 2019
Cited alongside, same era.
A little robustness goes a long way: Leveraging robust features for targeted transfer attacks
Jacob M Springer, Melanie Mitchell, and Garrett T Kenyon · 2021
Later among the works it cites.
Adversarially-trained deep nets transfer better: Illustration on image classification
Francisco Utrera, Evan Kravitz, N Benjamin Erichson, Rajiv Khanna, and Michael W Mahoney · 2021
Later among the works it cites.
Enhancing the transferability of adversarial attacks through variance tuning
Xiaosen Wang and Kun He · 2021
Later among the works it cites.
Admix: Enhancing the transferability of adversarial attacks
Xiaosen Wang, Xuanran He, Jingdong Wang, and Kun He · 2021
Later among the works it cites.
Boosting adversarial transferability through enhanced momentum
Xiaosen Wang, Jiadong Lin, Han Hu, Jingdong Wang, and Kun He · 2021
Later among the works it cites.
Feature importance-aware transferable adversarial attacks
Zhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu, Zhan Qin, and Kui Ren · 2021
Later among the works it cites.
Backpropagating smoothly improves transferability of adversarial examples
Chaoning Zhang, Philipp Benz, Gyusang Cho, Adil Karjauv, Soomin Ham, Chan-Hyun Youn, and In So Kweon · 2021
Later among the works it cites.
Early stop and adversarial training yield better surrogate model: Very non-robust features harm adversarial transferability
Chaoning Zhang, Gyusang Cho, Philipp Benz, Kang Zhang, Chenshuang Zhang, Chan-Hyun Youn, and In So Kweon · 2021
Later among the works it cites.
On success and simplicity: A second look at transferable targeted attacks
Zhengyu Zhao, Zhuoran Liu, and Martha Larson · 2021
Later among the works it cites.
Improving the transferability of targeted adversarial examples through object-based diverse input
Junyoung Byun, Seungju Cho, Myung-Joon Kwon, Hee-Seon Kim, and Changick Kim · 2022
Later among the works it cites.
Frequency domain model augmentation for adversarial attack
Yuyang Long, Qilong Zhang, Boheng Zeng, Lianli Gao, Xianglong Liu, Jian Zhang, and Jingkuan Song · 2022
Later among the works it cites.
Transfer attacks revisited: A large-scale empirical study in real computer vision settings
Yuhao Mao, Chong Fu, Saizhuo Wang, Shouling Ji, Xuhong Zhang, Zhenguang Liu, Jun Zhou, Alex X Liu, Raheem Beyah, and Ting Wang · 2022
Later among the works it cites.
Diffusion models for adversarial purification
Weili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao, Arash Vahdat, and Anima Anandkumar · 2022
Later among the works it cites.
Can neural nets learn the same model twice? investigating reproducibility and double descent from the decision boundary perspective
Gowthami Somepalli, Liam Fowl, Arpit Bansal, Ping Yeh-Chiang, Yehuda Dar, Richard Baraniuk, Micah Goldblum, and Tom Goldstein · 2022
Later among the works it cites.
Generating transferable adversarial examples against vision transformers
Yuxuan Wang, Jiakai Wang, Zixin Yin, Ruihao Gong, Jingyi Wang, Aishan Liu, and Xianglong Liu · 2022
Later among the works it cites.
Towards transferable adversarial attacks on vision transformers
Zhipeng Wei, Jingjing Chen, Micah Goldblum, Zuxuan Wu, Tom Goldstein, and Yu-Gang Jiang · 2022
Later among the works it cites.
Boosting transferability of targeted adversarial examples via hierarchical generative networks
Xiao Yang, Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu · 2022
Later among the works it cites.
Adaptive image transformations for transfer-based adversarial attack
Zheng Yuan, Jie Zhang, and Shiguang Shan · 2022
Later among the works it cites.
Improving adversarial transferability via neuron attribution-based attacks
Jianping Zhang, Weibin Wu, Jen-tse Huang, Yizhan Huang, Wenxuan Wang, Yuxin Su, and Michael R Lyu · 2022
Later among the works it cites.
Beyond imagenet attack: Towards crafting adversarial examples for black-box domains
Qilong Zhang, Xiaodan Li, Yuefeng Chen, Jingkuan Song, Lianli Gao, Yuan He, and Hui Xue · 2022
Later among the works it cites.
Rethinking adversarial transferability from a data distribution perspective
Yao Zhu, Jiacheng Sun, and Zhenguo Li · 2022
Later among the works it cites.
Measuring L ∞ L_{\infty} attacks by the L 2 L_{2} norm
Sizhe Chen, Qinghua Tao, Zhixing Ye, and Xiaolin Huang · 2023
Closest in time.
Evading black-box classifiers without breaking eggs
Edoardo Debenedetti, Nicholas Carlini, and Florian Tramèr · 2023
Closest in time.
Towards evaluating transfer-based attacks systematically, practically, and fairly
Qizhang Li, Yiwen Guo, Wangmeng Zuo, and Hao Chen · 2023
Closest in time.
Structure invariant transformation for better adversarial transferability
Xiaosen Wang, Zeliang Zhang, and Jianping Zhang · 2023
Closest in time.
Enhancing the self-universality for transferable targeted attacks
Zhipeng Wei, Jingjing Chen, Zuxuan Wu, and Yu-Gang Jiang · 2023
Closest in time.
Boosting the adversarial transferability of surrogate model with dark knowledge
Dingcheng Yang, Zihao Xiao, and Wenjian Yu · 2023
Closest in time.
Improving the transferability of adversarial samples by path-augmented method
Jianping Zhang, Jen-tse Huang, Wenxuan Wang, Yichen Li, Weibin Wu, Xiaosen Wang, Yuxin Su, and Michael R Lyu · 2023
Closest in time.
Transferable adversarial attacks on vision transformers with token gradient regularization
Jianping Zhang, Yizhan Huang, Weibin Wu, and Michael R Lyu · 2023
Closest in time.
Adversarial image color transformations in explicit color filter space
Zhengyu Zhao, Zhuoran Liu, and Martha Larson · 2023
Closest in time.
Defending against transfer attacks from public models
Chawin Sitawarin, Jaewon Chang, David Huang, Wesson Altoyan, and David Wagner · 2024
Closest in time.
Improving adversarial transferability on vision transformers via forward propagation refinement
Yuchen Ren, Zhengyu Zhao, Chenhao Lin, Bo Yang, Lu Zhou, Zhe Liu, and Chao Shen · 2025
Closest in time.
Improving integrated gradient-based transferable adversarial examples by refining the integration path
Yuchen Ren, Zhengyu Zhao, Chenhao Lin, Bo Yang, Lu Zhou, Zhe Liu, and Chao Shen · 2025
Closest in time.