English

Comment on Transferability and Input Transformation with Additive Noise

Machine Learning 2022-06-22 v1 Artificial Intelligence Cryptography and Security

Abstract

Adversarial attacks have verified the existence of the vulnerability of neural networks. By adding small perturbations to a benign example, adversarial attacks successfully generate adversarial examples that lead misclassification of deep learning models. More importantly, an adversarial example generated from a specific model can also deceive other models without modification. We call this phenomenon ``transferability". Here, we analyze the relationship between transferability and input transformation with additive noise by mathematically proving that the modified optimization can produce more transferable adversarial examples.

Keywords

Cite

@article{arxiv.2206.09075,
  title  = {Comment on Transferability and Input Transformation with Additive Noise},
  author = {Hoki Kim and Jinseong Park and Jaewook Lee},
  journal= {arXiv preprint arXiv:2206.09075},
  year   = {2022}
}
R2 v1 2026-06-24T11:55:45.347Z