Pith. sign in

REVIEW 4 major objections 4 minor 52 references

IGAff: Benchmarking Adversarial Iterative and Genetic Affine Algorithms on Deep Neural Networks

T0 review · 4 major / 4 minor · reviewed 2026-08-04 · deepseek-v4-flash

Pith's one-line read This paper claims that two output-only adversarial algorithms, one affine-iterative and one genetic, work as both attacks and data augmentation, with accuracy gains up to 8.82% over prior baselines and attack success rates above 60% on unde

desk verdict The 8.82% headline is an architecture gap, not an algorithm effect—but the empirical breadth deserves referee time if the authors fix the claims. read the letter →

arxiv 2509.06459 v1 pith:DQYGF7Z6 submitted 2025-09-08 cs.CV cs.LG

classification cs.CVcs.LG MSC 68T0768T4568W50
keywords adversarialattacksblack-boxgeneticalgorithmsaffinetransformationsdataaugmentationvisiontransformersrobustnessimageclassification
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper introduces and benchmarks two black-box iterative adversarial algorithms: ATA, which mutates images with random affine transformations and keeps the highest-scoring candidate, and AGA, which adds a genetic population, mutation, crossover, and noise to the same score-maximizing search. The authors claim both work as attacks and as data augmentation: training on adversarially augmented images raises classification accuracy, with a reported gain of up to 8.82% over similar methods in the literature, and the genetic variant is the stronger attack, reaching success rates above 60% on undefended transformers. They also report that transformer models are more vulnerable to undefended attacks but benefit disproportionately from adversarial augmentation, becoming more robust than CNNs. If true, the same cheap, model-agnostic perturbation recipe can expose model weaknesses and harden them without needing gradients or model internals.

What carries the argument

The attack score f_attack, a logistic (sigmoid) mapping of the model's cross-entropy loss, is the selection signal. ATA samples random affine transformations (rotation, translation, scaling, shearing) each iteration and keeps the candidate that maximizes f_attack, while AGA wraps the same score in a genetic loop: a population is mutated with affine transforms plus bounded uniform noise, recombined by swapping image rows, and the fittest individual is cloned to seed the next generation. This shared score function is what makes both algorithms black-box (only model outputs are needed) and what makes them usable in both attack and augmentation modes.

What would settle it

Train one architecture (for example, ViT on Tiny ImageNet-200) with exactly the same recipe, once with and once without ATA/AGA augmentation, and compare test accuracy; if accuracy does not rise, the augmentation claim collapses. Separately, run AGA with hard-label feedback only; if attack success drops sharply, the 'black-box' claim as framed, which uses soft cross-entropy losses, is not transferable to label-only settings.

Watch

Extended reading notes

Core claim

The paper's central claim is that a single parameter-light family of black-box image perturbations, built from affine transformations and (in one variant) genetic search, can serve both as an adversarial attack and as a data-augmentation tool. ATA repeatedly applies random rotations, translations, scalings, and shears, keeping the candidate that maximizes a logistic score over the model's cross-entropy loss; AGA adds a population, mutation with bounded noise, row-swap crossover, and elitist reselection around the same score. On Caltech-256, Food-101, and Tiny ImageNet-200, across ResNet-18, DenseNet-121, Swin Transformer V2, and ViT, the authors report that training with ATA/AGA-generated ad

Load-bearing premise

The results stand on the assumption that the reported accuracy differences come from the proposed algorithms rather than from architecture or training-recipe differences; the largest claimed gain compares a ViT trained without augmentation to CNN baselines from prior work, not a matched with/without ablation.

Editorial extensions

If this is right

  • If ATA/AGA are as effective as reported, practitioners can use one algorithm family for both robustness auditing and training-set expansion on image classifiers.
  • Transformer-focused robustness work should treat undefended transformers as high-risk: AGA reaches 63.97% attack success on an undefended ViT, so deploying unhardened ViTs may be riskier than CNNs.
  • Adversarial augmentation with the same algorithms is a viable defense: on Tiny ImageNet-200, AGA-augmented ViT drops attack success by 49.6 percentage points, the largest defense effect observed.
  • Because AGA's crossover probability has little effect while iterations, mutation probability, and noise intensity drive success, tuning effort can concentrate on the latter three.
  • ATA's stability across iterations (0.5-4% attack-success variation) makes it a drop-in augmentation module or a component for more complex attack pipelines.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The headline +8.82% compares a ViT without augmentation to prior CNN baselines; a same-architecture, same-recipe ablation would likely shrink the gap. The paper's augmentation value is better supported by the paired No Aug. versus ATA/AGA columns within each architecture.
  • The methods are black-box in the sense of needing no gradients or parameters, but they require soft outputs (cross-entropy losses); under a true label-only API, success rates would probably fall. A label-only variant would be a direct test.
  • Targeted attacks with negative success rates indicate that in some class/model combinations the 'attack' improves accuracy for that class, hinting that the same machinery could be used for targeted class repair rather than only confusion.
  • The crossover operator, swapping whole image rows, is crude and appears insensitive; recombination at the level of patches or feature maps might make the genetic search more effective.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. The paper proposes two black-box adversarial perturbation algorithms, Affine Transformation Attack (ATA) and Affine Genetic Attack (AGA), which combine random affine transformations and, for AGA, genetic operators and pixel noise. The authors benchmark these algorithms as data augmentation tools and as adversarial attacks on Tiny-ImageNet-200, Caltech-256, and Food-101, using ResNet-18, DenseNet-121, Swin Transformer V2, and Vision Transformer. They report attack success rates, targeted attack results, parameter sensitivity, and a qualitative comparison with Pixle and Square Attack. The abstract claims 'an accuracy improvement of up to 8.82%' over similar methods in the literature.

Significance. If the central claims were correct, the paper would offer simple, query-based black-box attacks and an augmentation scheme that improves classifier accuracy beyond prior affine-based methods. The experimental breadth is a genuine strength: three datasets, four architectures, repeated runs with means and standard deviations, and clearly written pseudocode for both algorithms. However, the headline accuracy improvement is not produced by the proposed algorithms: the 8.82% figure is an architecture/training-recipe difference between a no-augmentation ViT and CNN baselines from a different training setup, and the paper's own Table 1 shows that ATA and AGA augmentation frequently degrades accuracy relative to the same architecture without augmentation. The Pixle/Square comparison is anecdotal rather than a benchmark. Therefore the paper's main contribution, as stated, is not established, although the raw experimental material could be of interest if the claims were substantially reframed.

major comments (4)
  1. [Abstract; §4.1, Table 1] The '+8.82%' claim is an architecture gap, not an algorithm effect. On Tiny-ImageNet-200, the comparison is ViT with no augmentation (85.42%) versus Sandru et al.'s DenseNet-121 FLA (76.60%). This compares different architectures trained with different recipes, not ATA/AGA against a matched baseline. In the same ViT row, ATA (84.66%) and AGA (84.01%) are both lower than the no-augmentation result (85.42%). The central claim of accuracy improvement is therefore unsupported by the paper's own data; a matched same-architecture with/without augmentation comparison is required.
  2. [Table 1; §4.1] The data augmentation benefit of ATA/AGA is inconsistent and often negative. Examples: Tiny-ImageNet-200 ViT, ATA 84.66% and AGA 84.01% versus No Aug 85.42%; Caltech-256 DenseNet-121, ATA 84.41% and AGA 83.80% versus No Aug 84.47%; Food-101 ResNet-18, ATA 72.31% versus No Aug 72.99%. Many of these differences are within one standard deviation. Thus the statement that the algorithms 'outperform a similar method' in data augmentation is not supported.
  3. [§4.4, Fig. 6] The comparison with Pixle and Square Attack is qualitative and anecdotal: 12 selected images with success counts of 6/12 for ATA, 8/12 for AGA, 5/12 for Square, and 4/12 for Pixle. There is no query budget, no perturbation norm, no aggregate test-set metric, and no measure of variance or selection protocol. This cannot support the abstract's claim of benchmarking against these methods; a quantitative attack comparison under a defined protocol is needed.
  4. [§3.3, Alg. 1, Alg. 2] The 'black-box' setting is imprecise. Both algorithms compute CE(M(X), y), which requires soft scores or logits, not just hard labels. If 'black-box' is intended to mean gradient-free but score-based, the threat model should be stated explicitly and the comparison with Pixle/Square should account for the different information available to each method. As written, the algorithms do not operate in a decision-only black-box setting.
minor comments (4)
  1. [§3.1, Eq. (1)] The dataset diversity factor df is introduced but never used in the analysis. The text says 'We apply Eq. (1) to obtain balanced difficulty insights,' but no such insights are derived. Either use df in the discussion or remove it.
  2. [§3.4] The limitations sentence says 'we limited the population size (ni) to 3'; this should refer to the population size np, since ni is the number of iterations in Alg. 2.
  3. [§3.1] Tiny-ImageNet-200 is described as having 'a total of 550 images per class.' The standard split is 500 training and 50 validation images per class; the paper later splits data into train/validation/test 0.8/0.1/0.1. Please clarify which images are used and how the 550 figure is obtained.
  4. [§4.3, Figs. 5 and 7] The parameter-variation figures do not show error bars or confidence bands, even though the text quotes standard deviations up to 7–8%. Adding uncertainty information would make the sensitivity claims more interpretable.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: empirical benchmark; the headline 8.82% is an unsupported architecture comparison, not a derivation that reduces to its inputs.

full rationale

This paper is an empirical benchmark rather than a derivational chain, so none of the core claims reduce to fitted parameters, self-citations, or definitions by construction. The attack algorithms deliberately maximize the cross-entropy-based score fattack (Eq. 2) and success is measured by the resulting accuracy drop (Eq. 3); this is the intended optimization objective, not a hidden circular prediction. The paper cites prior work for inspiration (e.g., Athalye, Shen, Sandru) and contains no load-bearing self-citations or imported uniqueness theorems. The claimed '+8.82%' accuracy improvement is a cross-architecture comparison: Table 1 shows ViT without augmentation at 85.42% versus Sandru et al.'s CNN baselines at 76.60%, and on the same ViT row both ATA and AGA augmentations score lower (84.66% and 84.01%). That is an external-validity/attribution concern, not circularity: no equation in the paper is equivalent to its own input by construction, and no fitted parameter is renamed as a prediction. The augmentation and defense results are internally consistent with standard adversarial training behavior. Therefore, the circularity score is 0.

Assumptions & free parameters 7 free parameters · 4 assumptions · 1 invented entities

The central claims rest on hand-chosen algorithm parameters, a training recipe, and the attribution assumption that accuracy differences come from the attack algorithms rather than from architecture or training choices. The soft-loss access assumption also broadens what is meant by 'black-box'.

free parameters (7)
  • Number of iterations ni = 7 (default), varied 1-10
    Hand-chosen default for all main experiments; attack success varies with it.
  • Population size np = 3
    Hardware-limited choice; the paper notes memory constraints, so the genetic search is very small.
  • Mutation probability pm = 0.3
    Hand-chosen; varied in parameter sweep.
  • Crossover probability pc = 0.3
    Hand-chosen; varied in parameter sweep.
  • Adversarial noise intensity epsilon = 0.1
    Hand-chosen; varied in parameter sweep.
  • Affine sampling ranges = theta U(-3,3), translation U(-0.05,0.05), scale U(0.95,1.05), shear U(-1,1)
    Chosen to keep images visually close; ranges affect attack strength.
  • Training recipe = 12 epochs, batch 32, lr 1e-4, linear decay, 2 warmup epochs, Adam
    Hand-chosen training setup; accuracy comparisons against prior work depend on it.
assumptions (4)
  • domain assumption The model provides soft cross-entropy loss values to the attacker.
    Alg. 1 and Alg. 2 compute CE(M(X), y), which requires access to scores or logits, not just hard labels. This is stronger than a label-only black-box setting.
  • ad hoc to paper Training from scratch for 12 epochs is a fair basis for comparison with cited baselines.
    Sec. 3.4 fixes a single training recipe; the headline accuracy comparison against Sandru et al. uses different architectures and training conditions.
  • domain assumption The attack score fattack = sigmoid of cross-entropy loss is a valid selection criterion.
    Eq. (2) and Alg. 1/2 use this score without calibration to actual attack success rates.
  • ad hoc to paper The dataset diversity factor df introduced in Eq. (1) is a meaningful measure of dataset difficulty.
    The metric is used to justify dataset selection but is not validated against any external measure of difficulty.
invented entities (1)
  • Dataset diversity factor df
    purpose: Defined as average images per class divided by number of classes, used to frame dataset difficulty and justify choosing the three datasets.
    No evidence that df correlates with actual task difficulty or attack susceptibility; it is a descriptive ratio introduced for this paper.

how reviews work

0 comments
Cite this review

Pith. "Pith review of IGAff: Benchmarking Adversarial Iterative and Genetic Affine Algorithms on Deep Neural Networks." pith.science (2026). https://pith.science/paper/DQYGF7Z6

@misc{pith2026250906459,
  author       = {Pith},
  title        = {Pith review of: IGAff: Benchmarking Adversarial Iterative and Genetic Affine Algorithms on Deep Neural Networks},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/DQYGF7Z6}},
  note         = {Machine review of arXiv:2509.06459}
}
read the original abstract

Deep neural networks currently dominate many fields of the artificial intelligence landscape, achieving state-of-the-art results on numerous tasks while remaining hard to understand and exhibiting surprising weaknesses. An active area of research focuses on adversarial attacks, which aim to generate inputs that uncover these weaknesses. However, this proves challenging, especially in the black-box scenario where model details are inaccessible. This paper explores in detail the impact of such adversarial algorithms on ResNet-18, DenseNet-121, Swin Transformer V2, and Vision Transformer network architectures. Leveraging the Tiny ImageNet, Caltech-256, and Food-101 datasets, we benchmark two novel black-box iterative adversarial algorithms based on affine transformations and genetic algorithms: 1) Affine Transformation Attack (ATA), an iterative algorithm maximizing our attack score function using random affine transformations, and 2) Affine Genetic Attack (AGA), a genetic algorithm that involves random noise and affine transformations. We evaluate the performance of the models in the algorithm parameter variation, data augmentation, and global and targeted attack configurations. We also compare our algorithms with two black-box adversarial algorithms, Pixle and Square Attack. Our experiments yield better results on the image classification task than similar methods in the literature, achieving an accuracy improvement of up to 8.82%. We provide noteworthy insights into successful adversarial defenses and attacks at both global and targeted levels, and demonstrate adversarial robustness through algorithm parameter variation.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

52 extracted references · 38 canonical work pages

  1. [1]

    Alzantot, Y

    M. Alzantot, Y . Sharma, A. Elgohary, B.-J. Ho, M. Srivastava, and K.-W. Chang. Generating natural language adversarial examples. In E. Riloff, D. Chiang, J. Hockenmaier, and J. Tsujii, editors, Proceed- ings of the 2018 Conference on Empirical Methods in Natural Language Processing, pages 2890–2896, Brussels, Belgium, Oct.-Nov. 2018. As- sociation for Co...

  2. [2]

    Alzantot, Y

    M. Alzantot, Y . Sharma, S. Chakraborty, H. Zhang, C.-J. Hsieh, and M. B. Srivastava. Genattack: practical black-box attacks with gradient- free optimization. In Proceedings of the Genetic and Evolution- ary Computation Conference , GECCO ’19, page 1111–1119, New York, NY , USA, 2019. Association for Computing Machinery. ISBN 9781450361118. doi: 10.1145/3...

  3. [3]

    Andriushchenko, F

    M. Andriushchenko, F. Croce, N. Flammarion, and M. Hein. Square at- tack: A query-efficient black-box adversarial attack via random search. In Computer Vision – ECCV 2020: 16th European Conference, Glas- gow, UK, August 23–28, 2020, Proceedings, Part XXIII, page 484–501, Berlin, Heidelberg, 2020. Springer-Verlag. ISBN 978-3-030-58591-4. doi: 10.1007/978-3...

  4. [4]

    Athalye, L

    A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok. Synthesizing robust adversarial examples. In Proceedings of the 35th International Con- ference on Machine Learning , volume 80 of Proceedings of Machine Learning Research, pages 284–293. PMLR, 10–15 Jul 2018

  5. [5]

    Bossard, M

    L. Bossard, M. Guillaumin, and L. Van Gool. Food-101 – mining dis- criminative components with random forests. In D. Fleet, T. Pajdla, B. Schiele, and T. Tuytelaars, editors, Computer Vision – ECCV 2014, pages 446–461, Cham, 2014. Springer International Publishing. ISBN 978-3-319-10599-4

  6. [6]

    J. Byun, S. Cho, M.-J. Kwon, H.-S. Kim, and C. Kim. Improving the transferability of targeted adversarial examples through object-based diverse input. In Proceedings of the IEEE/CVF Conference on Com- puter Vision and Pattern Recognition (CVPR) , pages 15244–15253, June 2022

  7. [7]

    Carlini and D

    N. Carlini and D. Wagner. Towards evaluating the robustness of neu- ral networks. In 2017 IEEE Symposium on Security and Privacy (SP) , pages 39–57, 2017. doi: 10.1109/SP.2017.49

  8. [8]

    K. Deb, A. Pratap, S. Agarwal, and T. Meyarivan. A fast and elitist multiobjective genetic algorithm: Nsga-ii.IEEE Transactions on Evolu- tionary Computation, 6(2):182–197, 2002. doi: 10.1109/4235.996017

Show all 52 references
  1. [9]

    Demontis, M

    A. Demontis, M. Melis, M. Pintor, M. Jagielski, B. Biggio, A. Oprea, C. Nita-Rotaru, and F. Roli. Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks. In 28th USENIX Security Symposium (USENIX Security 19) , pages 321–338, Santa Cla...

  2. [10]

    Di Noia, D

    T. Di Noia, D. Malitesta, and F. A. Merra. Taamr: Targeted adver- sarial attack against multimedia recommender systems. In 2020 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W) , pages 1–8, 2020. doi: 10.1109/ DSN-W50199.2020.00011

  3. [11]

    Dosovitskiy, L

    A. Dosovitskiy, L. Beyer, A. Kolesnikov, D. Weissenborn, X. Zhai, T. Unterthiner, M. Dehghani, M. Minderer, G. Heigold, S. Gelly, J. Uszkoreit, and N. Houlsby. An image is worth 16x16 words: Trans- formers for image recognition at scale. In International Conference on Learning...

  4. [12]

    S. S. Ghosal and Y . Li. Are vision transformers robust to spurious cor- relations? Int. J. Comput. Vision , 132(3):689–709, oct 2023. ISSN 0920-5691. doi: 10.1007/s11263-023-01916-5

  5. [13]

    I. J. Goodfellow, J. Shlens, and C. Szegedy. Explaining and harnessing adversarial examples. In Y . Bengio and Y . LeCun, editors,3rd Interna- tional Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, 2015

  6. [14]

    Griffin, A

    G. Griffin, A. Holub, and P. Perona. Caltech 256, Apr 2022

  7. [15]

    Gu and L

    S. Gu and L. Rigazio. Towards deep neural network architectures ro- bust to adversarial examples. In Y . Bengio and Y . LeCun, editors, 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Workshop Track Proceedings, 2015

  8. [16]

    K. He, X. Zhang, S. Ren, and J. Sun. Deep residual learning for im- age recognition. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), June 2016

  9. [17]

    J. Holland. Adaptation in Natural and Artificial Systems: An Intro- ductory Analysis with Applications to Biology, Control, and Artificial Intelligence. Complex Adaptive Systems. MIT Press, 1992. ISBN 9780262581110

  10. [18]

    Huang, Z

    G. Huang, Z. Liu, L. van der Maaten, and K. Q. Weinberger. Densely connected convolutional networks. In Proceedings of the IEEE Confer- ence on Computer Vision and Pattern Recognition, 2017

  11. [19]

    D. P. Kingma and J. Ba. Adam: A method for stochastic optimization. In Y . Bengio and Y . LeCun, editors, 3rd International Conference on Learning Representations, ICLR 2015, San Diego,USA, May 7-9, 2015

  12. [20]

    H. Kwon, Y . Kim, K.-W. Park, H. Yoon, and D. Choi. Multi-targeted adversarial example in evasion attack on deep neural network. IEEE Access, 6:46084–46096, 2018. doi: 10.1109/ACCESS.2018.2866197

  13. [21]

    LeCun, C

    Y . LeCun, C. Cortes, and C. Burges. Mnist handwritten digit database. ATT Labs [Online]. Available: http://yann.lecun.com/exdb/mnist , 2, 2010

  14. [22]

    F. Li, L. Tran, K.-H. Thung, S. Ji, D. Shen, and J. Li. A robust deep model for improved classification of ad/mci patients. IEEE Journal of Biomedical and Health Informatics , 19(5):1610–1616, 2015. doi: 10.1109/JBHI.2015.2429556

  15. [23]

    Z. Liu, Y . Lin, Y . Cao, H. Hu, Y . Wei, Z. Zhang, S. Lin, and B. Guo. Swin transformer: Hierarchical vision transformer using shifted win- dows. In 2021 IEEE/CVF International Conference on Computer Vi- sion (ICCV), pages 9992–10002, Los Alamitos, CA, USA, oct 2021. IEEE Com...

  16. [24]

    Z. Liu, H. Hu, Y . Lin, Z. Yao, Z. Xie, Y . Wei, J. Ning, Y . Cao, Z. Zhang, L. Dong, F. Wei, and B. Guo. Swin transformer v2: Scaling up ca- pacity and resolution. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , pages 12009– 12019...

  17. [25]

    Madry, A

    A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu. Towards deep learning models resistant to adversarial attacks. In 6th Interna- tional Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings , 2018

  18. [27]

    Marchisio, A

    A. Marchisio, A. De Marco, A. Colucci, M. Martina, and M. Shafique. Robcaps: Evaluating the robustness of capsule networks against affine transformations and adversarial attacks. In 2023 International Joint Conference on Neural Networks (IJCNN) , pages 1–9, 2023. doi: 10.1109/...

  19. [28]

    G. A. Miller. WordNet: A lexical database for English. In Human Language Technology: Proceedings of a Workshop held at Plainsboro, New Jersey, March 8-11, 1994, 1994

  20. [29]

    Naseer, K

    M. Naseer, K. Ranasinghe, S. Khan, F. S. Khan, and F. Porikli. On im- proving adversarial transferability of vision transformers. In The Tenth International Conference on Learning Representations, ICLR 2022, Vir- tual Event, April 25-29, 2022, 2022

  21. [30]

    NeuroEvolution of Augmenting Topolo- gies

    E. Papavasileiou, J. Cornelis, and B. Jansen. A Systematic Literature Review of the Successors of “NeuroEvolution of Augmenting Topolo- gies”. Evolutionary Computation, 29(1):1–73, 03 2021. ISSN 1063-

  22. [31]

    Pomponi, S

    J. Pomponi, S. Scardapane, and A. Uncini. Pixle: a fast and effective black-box attack based on rearranging pixels. In 2022 International Joint Conference on Neural Networks (IJCNN) , pages 1–7, 2022. doi: 10.1109/IJCNN55064.2022.9892966

  23. [32]

    Pomponi, S

    J. Pomponi, S. Scardapane, and A. Uncini. Pixle: a fast and effective black-box attack based on rearranging pixels. 2022 International Joint Conference on Neural Networks (IJCNN), pages 1–7, 2022

  24. [33]

    Rathore, P

    H. Rathore, P. B, S. S. Iyengar, and S. K. Sahay. Breaking the anti- malware: Evoaattack based on genetic algorithm against android mal- ware detection systems. In J. Mikyška, C. de Mulatier, M. Paszynski, V . V . Krzhizhanovskaya, J. J. Dongarra, and P. M. Sloot, editors,Com-...

  25. [34]

    Russakovsky, J

    O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. Bernstein, A. C. Berg, and L. Fei- Fei. Imagenet large scale visual recognition challenge. International Journal of Computer Vision, 115(3):211–252, Dec 2015. ISSN 1573-

  26. [35]

    Sandru, M.-I

    A. Sandru, M.-I. Georgescu, and R. T. Ionescu. Feature-level augmenta- tion to improve robustness of deep neural networks to affine transforma- tions. In L. Karlinsky, T. Michaeli, and K. Nishino, editors, Computer Vision – ECCV 2022 Workshops, pages 332–341, Cham, 2023. Sprin...

  27. [36]

    M. L. Seltzer, D. Yu, and Y . Wang. An investigation of deep neural networks for noise robust speech recognition. In 2013 IEEE Interna- tional Conference on Acoustics, Speech and Signal Processing , pages 7398–7402, 2013. doi: 10.1109/ICASSP.2013.6639100

  28. [37]

    R. Shao, Z. Shi, J. Yi, P. Chen, and C. Hsieh. On the adversarial robust- ness of vision transformers. Trans. Mach. Learn. Res., 2022, 2022

  29. [38]

    G. Shen, W. Huang, C. Gan, M. Tan, J. Huang, W. Zhu, and B. Gong. Facial image-to-video translation by a hidden affine transformation. In Proceedings of the 27th ACM International Conference on Multimedia, MM ’19, page 2505–2513, New York, NY , USA, 2019. Association for Compu...

  30. [39]

    Stanley and R

    K. Stanley and R. Miikkulainen. Efficient evolution of neural network topologies. In Proceedings of the 2002 Congress on Evolutionary Com- putation. CEC’02 (Cat. No.02TH8600) , volume 2, pages 1757–1762 vol.2, 2002. doi: 10.1109/CEC.2002.1004508

  31. [40]

    A. P. Steiner, A. Kolesnikov, X. Zhai, R. Wightman, J. Uszkoreit, and L. Beyer. How to train your vit? data, augmentation, and regularization in vision transformers. Transactions on Machine Learning Research ,

  32. [41]

    B. Sun, H. Su, and S. Zheng. Black-box attacks on face recognition via affine-invariant training. Neural Computing and Applications , 36(15): 8549–8564, May 2024. doi: 10.1007/s00521-024-09543-y

  33. [42]

    Sun, H.-x

    S. Sun, H.-x. Hou, Z.-h. Yang, Y .-s. Wang, and N.-e. Wu. Generat- ing adversarial examples for low-resource nmt via multi-reward rein- forcement learning. In 2022 IEEE 34th International Conference on Tools with Artificial Intelligence (ICTAI), pages 1175–1180, 2022. doi: 10....

  34. [43]

    Szegedi, P

    G. Szegedi, P. Kiss, and T. Horváth. Evolutionary federated learning on eeg-data. In Conference on Theory and Practice of Information Tech- nologies, 2019

  35. [44]

    Szegedy, W

    C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfel- low, and R. Fergus. Intriguing properties of neural networks. In Y . Ben- gio and Y . LeCun, editors, 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2...

  36. [45]

    Szegedy, W

    C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfel- low, and R. Fergus. Intriguing properties of neural networks. In Y . Ben- gio and Y . LeCun, editors, 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2014

  37. [46]

    Taori, A

    R. Taori, A. Kamsetty, B. Chu, and N. Vemuri. Targeted adversarial ex- amples for black box audio systems. In2019 IEEE Security and Privacy Workshops (SPW), pages 15–20, 2019. doi: 10.1109/SPW.2019.00016

  38. [47]

    P. Tian, S. Poreddy, C. Danda, C. Gowrineni, Y . Wu, and W. Liao. Evaluating impact of image transformations on adversarial examples. IEEE Access, 12:186217–186228, 2024. doi: 10.1109/ACCESS.2024. 3487479

  39. [48]

    Vaswani, N

    A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, L. u. Kaiser, and I. Polosukhin. Attention is all you need. In I. Guyon, U. V . Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vish- wanathan, and R. Garnett, editors,Advances in Neural Information Pro- ces...

  40. [49]

    Waseda, S

    F. Waseda, S. Nishikawa, T.-N. Le, H. H. Nguyen, and I. Echizen. Closer look at the transferability of adversarial examples: How they fool different models differently. 2023 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV), pages 1360–1368, 2021

  41. [50]

    Q. You, J. Luo, H. Jin, and J. Yang. Robust image sentiment analysis using progressively trained and domain transferred deep networks.Pro- ceedings of the AAAI Conference on Artificial Intelligence , 29(1), Feb

  42. [1405]

    doi: 10.1007/s11263-015-0816-y

  43. [2015]

    doi: 10.1609/aaai.v29i1.9179

  44. [6560]

    doi: 10.1162/evco_a_00282

Pith tools

Reviewed August 4, 2026 · model on record in the stance chip above.