paper-with-me

홈 › Papers

Towards Good Practices in Evaluating Transfer Adversarial Attacks

2022-11-17 · Zhengyu Zhao, Hanwei Zhang, Renjue Li, Ronan Sicre, Laurent Amsaleg, Michael Backes

Transfer adversarial attacks raise critical security concerns in real-world, black-box scenarios. However, the actual progress of this field is difficult to assess due to two common limitations in existing evaluations. First, different methods are often not systematically and fairly evaluated in a one-to-one comparison. Second, only transferability is evaluated but another key attack property, stealthiness, is largely overlooked. In this work, we design good practices to address these limitations, and we present the first comprehensive evaluation of transfer attacks, covering 23 representative attacks against 9 defenses on ImageNet. In particular, we propose to categorize existing attacks into five categories, which enables our systematic category-wise analyses. These analyses lead to new findings that even challenge existing knowledge and also help determine the optimal attack hyperparameters for our attack-wise comprehensive evaluation. We also pay particular attention to stealthiness, by adopting diverse imperceptibility metrics and looking into new, finer-grained characteristics. Overall, our new insights into transferability and stealthiness lead to actionable good practices for future evaluations.

📄 PDF Abstract BibTeX arXiv:2211.09565

Code (1)

zhengyuzhao/transferattackeval 공식 구현 pytorch

Similar Papers 제목 키워드 기반

Devling into Adversarial Transferability on Image Classification: Review, Benchmark, and Evaluation

2026-02-26 · Xiaosen Wang, Zhijin Ge, Bohan Liu, Zheng Fang 외 arxiv

Adversarial transferability refers to the capacity of adversarial examples generated on the surrogate model to deceive alternate, unexposed victim models. This property eliminates the need for direct access to the victim…

Image Classification

On Evaluating Adversarial Robustness

2019-02-18 · Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel 외

Correctly evaluating defenses against adversarial examples has proven to be extremely difficult. Despite the significant amount of recent work attempting to design defenses that withstand adaptive attacks, few have succe…

Adversarial AttackAdversarial DefenseAdversarial Robustness

On Evaluating Adversarial Robustness of Chest X-ray Classification: Pitfalls and Best Practices

2022-12-15 · Salah Ghamizi, Maxime Cordy, Michail Papadakis, Yves Le Traon

Vulnerability to adversarial attacks is a well-known weakness of Deep Neural Networks. While most of the studies focus on natural images with standardized benchmarks like ImageNet and CIFAR, little research has considere…

Adversarial RobustnessClassificationMedical DiagnosisX-ray Classification

I Stolenly Swear That I Am Up to (No) Good: Design and Evaluation of Model Stealing Attacks

2025-08-29 · Daryna Oliynyk, Rudolf Mayer, Kathrin Grosse, Andreas Rauber arxiv

Model stealing attacks endanger the confidentiality of machine learning models offered as a service. Although these models are kept secret, a malicious party can query a model to label data samples and train their own su…

Image Classification

Recent improvements of ASR models in the face of adversarial attacks

2022-03-29 · Raphael Olivier, Bhiksha Raj

Like many other tasks involving neural networks, Speech Recognition models are vulnerable to adversarial attacks. However recent research has pointed out differences between attacks and defenses on ASR models compared to…

speech-recognitionSpeech Recognition