{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2016:Y55GUQUYDQF4N3D6JMQCQ5QIZO","short_pith_number":"pith:Y55GUQUY","schema_version":"1.0","canonical_sha256":"c77a6a42981c0bc6ec7e4b20287608cb8e9f41a73c07e4033ca314c78ad94125","source":{"kind":"arxiv","id":"1611.02770","version":3},"attestation_state":"computed","paper":{"title":"Delving into Transferable Adversarial Examples and Black-box Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Chang Liu, Dawn Song, Xinyun Chen, Yanpei Liu","submitted_at":"2016-11-08T23:25:00Z","abstract_excerpt":"An intriguing property of deep neural networks is the existence of adversarial examples, which can transfer among different architectures. These transferable adversarial examples may severely hinder deep neural network-based applications. Previous works mostly study the transferability using small scale datasets. In this work, we are the first to conduct an extensive study of the transferability over large models and a large scale dataset, and we are also the first to study the transferability of targeted adversarial examples with their target labels. We study both non-targeted and targeted ad"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1611.02770","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-11-08T23:25:00Z","cross_cats_sorted":[],"title_canon_sha256":"ad2152885ae9a98bd0267c884a9167f22d714c4246cbfa9a203e73b68f300e75","abstract_canon_sha256":"57e1373a032f97c25376b26fdd6a86838e0f27840a0866bbeb68615ffc7cf66d"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:51:13.239686Z","signature_b64":"9LWrZBwXgpufg7OnKZRKd0XjMrzgXhqTsyqeAbO8Yvc/Y1TWK8+BiF/+MZn82NFrMazBxaxTfv0HSN4kUrziDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c77a6a42981c0bc6ec7e4b20287608cb8e9f41a73c07e4033ca314c78ad94125","last_reissued_at":"2026-05-18T00:51:13.238918Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:51:13.238918Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Delving into Transferable Adversarial Examples and Black-box Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Chang Liu, Dawn Song, Xinyun Chen, Yanpei Liu","submitted_at":"2016-11-08T23:25:00Z","abstract_excerpt":"An intriguing property of deep neural networks is the existence of adversarial examples, which can transfer among different architectures. These transferable adversarial examples may severely hinder deep neural network-based applications. Previous works mostly study the transferability using small scale datasets. In this work, we are the first to conduct an extensive study of the transferability over large models and a large scale dataset, and we are also the first to study the transferability of targeted adversarial examples with their target labels. We study both non-targeted and targeted ad"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1611.02770","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1611.02770","created_at":"2026-05-18T00:51:13.239042+00:00"},{"alias_kind":"arxiv_version","alias_value":"1611.02770v3","created_at":"2026-05-18T00:51:13.239042+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1611.02770","created_at":"2026-05-18T00:51:13.239042+00:00"},{"alias_kind":"pith_short_12","alias_value":"Y55GUQUYDQF4","created_at":"2026-05-18T12:30:53.716459+00:00"},{"alias_kind":"pith_short_16","alias_value":"Y55GUQUYDQF4N3D6","created_at":"2026-05-18T12:30:53.716459+00:00"},{"alias_kind":"pith_short_8","alias_value":"Y55GUQUY","created_at":"2026-05-18T12:30:53.716459+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":16,"internal_anchor_count":11,"sample":[{"citing_arxiv_id":"1906.09288","citing_title":"Hiding Faces in Plain Sight: Disrupting AI Face Synthesis with Adversarial Perturbations","ref_index":56,"is_internal_anchor":true},{"citing_arxiv_id":"1907.00374","citing_title":"Fooling a Real Car with Adversarial Traffic Signs","ref_index":26,"is_internal_anchor":true},{"citing_arxiv_id":"1907.00118","citing_title":"Cellular State Transformations using Generative Adversarial Networks","ref_index":18,"is_internal_anchor":true},{"citing_arxiv_id":"2406.09250","citing_title":"MirrorCheck: Efficient Adversarial Defense for Vision-Language Models","ref_index":58,"is_internal_anchor":true},{"citing_arxiv_id":"1907.06800","citing_title":"Graph Interpolating Activation Improves Both Natural and Robust Accuracies in Data-Efficient Deep Learning","ref_index":11,"is_internal_anchor":true},{"citing_arxiv_id":"2209.03358","citing_title":"Attacking the Spike: On the Transferability and Security of Spiking Neural Networks to Adversarial Examples","ref_index":21,"is_internal_anchor":true},{"citing_arxiv_id":"2404.02696","citing_title":"Deep Privacy Funnel Model: From a Discriminative to a Generative Approach with an Application to Face Recognition","ref_index":133,"is_internal_anchor":true},{"citing_arxiv_id":"2605.17772","citing_title":"Towards Universal Physical Adversarial Attacks via a Joint Multi-Objective and Multi-Model Optimization Framework","ref_index":39,"is_internal_anchor":true},{"citing_arxiv_id":"2512.10275","citing_title":"Sample-wise Adaptive Weighting for Transfer Consistency in Adversarial Distillation","ref_index":47,"is_internal_anchor":true},{"citing_arxiv_id":"2601.14505","citing_title":"Uncovering and Understanding FPR Manipulation Attack in Industrial IoT Networks","ref_index":75,"is_internal_anchor":true},{"citing_arxiv_id":"2605.12792","citing_title":"SoK: A Comprehensive Analysis of the Current Status of Neural Tangent Generalization Attacks with Research Directions","ref_index":55,"is_internal_anchor":true},{"citing_arxiv_id":"2310.08419","citing_title":"Jailbreaking Black Box Large Language Models in Twenty Queries","ref_index":52,"is_internal_anchor":false},{"citing_arxiv_id":"2209.10652","citing_title":"Toy Models of Superposition","ref_index":15,"is_internal_anchor":false},{"citing_arxiv_id":"2605.04261","citing_title":"Laundering AI Authority with Adversarial Examples","ref_index":36,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01221","citing_title":"Local Hessian Spectral Filtering for Robust Intrinsic Dimension Estimation","ref_index":274,"is_internal_anchor":false},{"citing_arxiv_id":"2604.16532","citing_title":"Beyond Attack Success Rate: A Multi-Metric Evaluation of Adversarial Transferability in Medical Imaging Models","ref_index":13,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/Y55GUQUYDQF4N3D6JMQCQ5QIZO","json":"https://pith.science/pith/Y55GUQUYDQF4N3D6JMQCQ5QIZO.json","graph_json":"https://pith.science/api/pith-number/Y55GUQUYDQF4N3D6JMQCQ5QIZO/graph.json","events_json":"https://pith.science/api/pith-number/Y55GUQUYDQF4N3D6JMQCQ5QIZO/events.json","paper":"https://pith.science/paper/Y55GUQUY"},"agent_actions":{"view_html":"https://pith.science/pith/Y55GUQUYDQF4N3D6JMQCQ5QIZO","download_json":"https://pith.science/pith/Y55GUQUYDQF4N3D6JMQCQ5QIZO.json","view_paper":"https://pith.science/paper/Y55GUQUY","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1611.02770&json=true","fetch_graph":"https://pith.science/api/pith-number/Y55GUQUYDQF4N3D6JMQCQ5QIZO/graph.json","fetch_events":"https://pith.science/api/pith-number/Y55GUQUYDQF4N3D6JMQCQ5QIZO/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/Y55GUQUYDQF4N3D6JMQCQ5QIZO/action/timestamp_anchor","attest_storage":"https://pith.science/pith/Y55GUQUYDQF4N3D6JMQCQ5QIZO/action/storage_attestation","attest_author":"https://pith.science/pith/Y55GUQUYDQF4N3D6JMQCQ5QIZO/action/author_attestation","sign_citation":"https://pith.science/pith/Y55GUQUYDQF4N3D6JMQCQ5QIZO/action/citation_signature","submit_replication":"https://pith.science/pith/Y55GUQUYDQF4N3D6JMQCQ5QIZO/action/replication_record"}},"created_at":"2026-05-18T00:51:13.239042+00:00","updated_at":"2026-05-18T00:51:13.239042+00:00"}