Pith. sign in

REVIEW 3 cited by

Reliable Evaluation of Adversarial Transferability

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2306.08565 v1 pith:R2KXNAND submitted 2023-06-14 cs.CV

classification cs.CV
keywords adversarialtransferabilityevaluationbenchmarkneuralreliablemethodsmodels
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Adversarial examples (AEs) with small adversarial perturbations can mislead deep neural networks (DNNs) into wrong predictions. The AEs created on one DNN can also fool another DNN. Over the last few years, the transferability of AEs has garnered significant attention as it is a crucial property for facilitating black-box attacks. Many approaches have been proposed to improve adversarial transferability. However, they are mainly verified across different convolutional neural network (CNN) architectures, which is not a reliable evaluation since all CNNs share some similar architectural biases. In this work, we re-evaluate 12 representative transferability-enhancing attack methods where we test on 18 popular models from 4 types of neural networks. Our reevaluation revealed that the adversarial transferability is often overestimated, and there is no single AE that can be transferred to all popular models. The transferability rank of previous attacking methods changes when under our comprehensive evaluation. Based on our analysis, we propose a reliable benchmark including three evaluation protocols. Adversarial transferability on our new benchmark is extremely low, which further confirms the overestimation of adversarial transferability. We release our benchmark at https://adv-trans-eval.github.io to facilitate future research, which includes code, model checkpoints, and evaluation protocols.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. The VORTEX cavity for the RADES axion haloscope

    physics.ins-det 2026-07 conditional novelty 5.0 of 10

    A split-cylinder axion haloscope tunes continuously from 9 to 8.2 GHz with modest Q loss, operates at millikelvin temperatures, and its TM010 field profile passes bead-pull verification.

  2. DUMB and DUMBer: Is Adversarial Training Worth It in the Real World?

    cs.CR 2025-06 conditional novelty 5.0 of 10

    Across 240 model configurations and 13 attacks, adaptive and curriculum adversarial training give the largest robustness gains, but 20.53% of evaluations show negative gains, mostly under mismatched source-target mode...

  3. Experiments to test the hypothesis for solar and dark matter axions

    hep-ph 2025-07 unverdicted novelty 1.0 of 10

    This is a pedagogical review of haloscope and helioscope experiments searching for dark matter and solar axions, with an overview of near-future technological developments.

Pith tools