{"id":"https://openalex.org/W4223544745","doi":"https://doi.org/10.1109/sp46214.2022.9833783","title":"Transfer Attacks Revisited: A Large-Scale Empirical Study in Real Computer Vision Settings","display_name":"Transfer Attacks Revisited: A Large-Scale Empirical Study in Real Computer Vision Settings","publication_year":2022,"publication_date":"2022-05-01","ids":{"openalex":"https://openalex.org/W4223544745","doi":"https://doi.org/10.1109/sp46214.2022.9833783"},"language":"en","primary_location":{"id":"doi:10.1109/sp46214.2022.9833783","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833783","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5104195489","display_name":"Yuhao Mao","orcid":null},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yuhao Mao","raw_affiliation_strings":["Zhejiang University"],"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074242762","display_name":"Chong Fu","orcid":"https://orcid.org/0000-0002-4549-744X"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chong Fu","raw_affiliation_strings":["Zhejiang University"],"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022061281","display_name":"Saizhuo Wang","orcid":"https://orcid.org/0000-0001-8175-8451"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Saizhuo Wang","raw_affiliation_strings":["Zhejiang University"],"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058611515","display_name":"Shouling Ji","orcid":"https://orcid.org/0000-0003-4268-372X"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shouling Ji","raw_affiliation_strings":["Zhejiang University"],"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101722406","display_name":"Xuhong Zhang","orcid":"https://orcid.org/0000-0002-8571-9780"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xuhong Zhang","raw_affiliation_strings":["Zhejiang University","Zhejiang University NGICS Platform"],"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]},{"raw_affiliation_string":"Zhejiang University NGICS Platform","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101715620","display_name":"Zhenguang Liu","orcid":"https://orcid.org/0000-0002-7981-9873"},"institutions":[{"id":"https://openalex.org/I75059550","display_name":"Zhejiang Gongshang University","ror":"https://ror.org/0569mkk41","country_code":"CN","type":"education","lineage":["https://openalex.org/I75059550"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhenguang Liu","raw_affiliation_strings":["Zhejiang Gongshang University"],"affiliations":[{"raw_affiliation_string":"Zhejiang Gongshang University","institution_ids":["https://openalex.org/I75059550"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100781212","display_name":"Jun Zhou","orcid":"https://orcid.org/0000-0001-5822-8233"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jun Zhou","raw_affiliation_strings":["Ant Group"],"affiliations":[{"raw_affiliation_string":"Ant Group","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008787905","display_name":"Alex X. Liu","orcid":"https://orcid.org/0000-0002-6916-1326"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Alex X. Liu","raw_affiliation_strings":["Ant Group"],"affiliations":[{"raw_affiliation_string":"Ant Group","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5033073212","display_name":"Raheem Beyah","orcid":"https://orcid.org/0000-0002-9188-3464"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Raheem Beyah","raw_affiliation_strings":["Georgia Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100428026","display_name":"Ting Wang","orcid":"https://orcid.org/0000-0003-4927-5833"},"institutions":[{"id":"https://openalex.org/I130769515","display_name":"Pennsylvania State University","ror":"https://ror.org/04p491231","country_code":"US","type":"education","lineage":["https://openalex.org/I130769515"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ting Wang","raw_affiliation_strings":["Pennsylvania State University"],"affiliations":[{"raw_affiliation_string":"Pennsylvania State University","institution_ids":["https://openalex.org/I130769515"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":10,"corresponding_author_ids":["https://openalex.org/A5104195489"],"corresponding_institution_ids":["https://openalex.org/I76130692"],"apc_list":null,"apc_paid":null,"fwci":1.2473,"has_fulltext":false,"cited_by_count":12,"citation_normalized_percentile":{"value":0.80941607,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1423","last_page":"1439"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10645","display_name":"Cardiac Arrest and Resuscitation","score":0.9200000166893005,"subfield":{"id":"https://openalex.org/subfields/2711","display_name":"Emergency Medicine"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.7706584930419922},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7401226162910461},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5339414477348328},{"id":"https://openalex.org/keywords/transfer-of-learning","display_name":"Transfer of learning","score":0.5236625075340271},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.4956117868423462},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.42525067925453186},{"id":"https://openalex.org/keywords/logit","display_name":"Logit","score":0.28834068775177}],"concepts":[{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.7706584930419922},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7401226162910461},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5339414477348328},{"id":"https://openalex.org/C150899416","wikidata":"https://www.wikidata.org/wiki/Q1820378","display_name":"Transfer of learning","level":2,"score":0.5236625075340271},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.4956117868423462},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.42525067925453186},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.28834068775177}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/sp46214.2022.9833783","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833783","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":59,"referenced_works":["https://openalex.org/W129305155","https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1945616565","https://openalex.org/W1965804146","https://openalex.org/W2097117768","https://openalex.org/W2108598243","https://openalex.org/W2112796928","https://openalex.org/W2180612164","https://openalex.org/W2183341477","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2408141691","https://openalex.org/W2543927648","https://openalex.org/W2562637781","https://openalex.org/W2570685808","https://openalex.org/W2603766943","https://openalex.org/W2620038827","https://openalex.org/W2746600820","https://openalex.org/W2787970001","https://openalex.org/W2887603965","https://openalex.org/W2896457183","https://openalex.org/W2902543210","https://openalex.org/W2963062382","https://openalex.org/W2963389226","https://openalex.org/W2963542245","https://openalex.org/W2963744840","https://openalex.org/W2963857521","https://openalex.org/W2970597249","https://openalex.org/W2975763460","https://openalex.org/W2996141621","https://openalex.org/W2999606423","https://openalex.org/W3080260826","https://openalex.org/W3094250460","https://openalex.org/W3106412272","https://openalex.org/W3113251160","https://openalex.org/W3118608800","https://openalex.org/W3210951978","https://openalex.org/W4221161648","https://openalex.org/W4252684946","https://openalex.org/W4289549047","https://openalex.org/W4293846201","https://openalex.org/W4385245566","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6640425456","https://openalex.org/W6714069269","https://openalex.org/W6719080892","https://openalex.org/W6731927902","https://openalex.org/W6739868092","https://openalex.org/W6748406123","https://openalex.org/W6750404860","https://openalex.org/W6755207826","https://openalex.org/W6757702690","https://openalex.org/W6759424558","https://openalex.org/W6763701032","https://openalex.org/W6787777936","https://openalex.org/W6802757820","https://openalex.org/W6810643141"],"related_works":["https://openalex.org/W4288055406","https://openalex.org/W3092178728","https://openalex.org/W4226402597","https://openalex.org/W4200630034","https://openalex.org/W3137894200","https://openalex.org/W3132910851","https://openalex.org/W4377864639","https://openalex.org/W2997056298","https://openalex.org/W2950864148","https://openalex.org/W2570685808"],"abstract_inverted_index":{"One":[0],"intriguing":[1],"property":[2],"of":[3,52,75,86,99,139,190,198,221],"adversarial":[4,11],"attacks":[5,57,77,165],"is":[6,23,48,125,133,179,201],"their":[7],"\u201ctransferability\u201d":[8],"\u2013":[9],"an":[10],"example":[12],"crafted":[13],"with":[14,158],"respect":[15],"to":[16,96,105,227],"one":[17],"deep":[18],"neural":[19],"network":[20],"(DNN)":[21],"model":[22],"often":[24],"found":[25,126],"effective":[26],"against":[27,78],"other":[28],"DNNs":[29],"as":[30,175],"well.":[31],"Intensive":[32],"research":[33,231],"has":[34],"been":[35],"conducted":[36],"on":[37,218],"this":[38,64,214],"phenomenon":[39],"under":[40],"simplistic":[41],"controlled":[42],"conditions.":[43],"Yet,":[44],"thus":[45],"far":[46],"there":[47],"still":[49],"a":[50,87,97,181,202,228],"lack":[51],"comprehensive":[53],"understanding":[54],"about":[55],"transferability-based":[56],"(\u201ctransfer":[58],"attacks\u201d)":[59],"in":[60,127,171],"real-world":[61,172],"environments.To":[62],"bridge":[63],"critical":[65],"gap,":[66],"we":[67,161],"conduct":[68],"the":[69,84,106,134,140,145,219],"first":[70],"large-scale":[71],"systematic":[72],"empirical":[73],"study":[74,94],"transfer":[76,89,118,129,164],"major":[79],"cloud-based":[80],"MLaaS":[81,223],"platforms,":[82],"taking":[83],"components":[85],"real":[88,117,128],"attack":[90],"into":[91],"account.":[92],"The":[93],"leads":[95],"number":[98],"interesting":[100],"findings":[101],"which":[102],"are":[103],"inconsistent":[104],"existing":[107],"ones,":[108],"including:":[109],"(i)":[110,176],"Simple":[111],"surrogates":[112],"do":[113],"not":[114,180],"necessarily":[115],"improve":[116],"attacks.":[119,130],"(ii)":[120,184],"No":[121],"dominant":[122],"surrogate":[123],"architecture":[124],"(iii)":[131],"It":[132],"gap":[135,146],"between":[136,147],"posterior":[137],"(output":[138],"softmax":[141],"layer)":[142],"rather":[143],"than":[144,206],"logit":[148],"(so-called":[149],"\u03ba":[150],"value)":[151],"that":[152,163],"increases":[153],"transferability.":[154],"Moreover,":[155],"by":[156],"comparing":[157],"prior":[159],"works,":[160],"demonstrate":[162],"possess":[166],"many":[167],"previously":[168],"unknown":[169],"properties":[170],"environments,":[173],"such":[174],"Model":[177],"similarity":[178],"well-defined":[182],"concept.":[183],"L":[185,207],"<inf":[186,208],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[187,209,234],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">2</inf>":[188],"norm":[189],"perturbation":[191],"can":[192],"generate":[193],"high":[194],"transferability":[195],"without":[196],"usage":[197],"gradient":[199],"and":[200,225],"more":[203],"powerful":[204],"source":[205],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">\u221e</inf>":[210],"norm.":[211],"We":[212],"believe":[213],"work":[215],"sheds":[216],"light":[217],"vulnerabilities":[220],"popular":[222],"platforms":[224],"points":[226],"few":[229],"promising":[230],"directions.":[232],"<sup":[233],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">1</sup>":[235]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":7},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
