{"id":"https://openalex.org/W3208594240","doi":"https://doi.org/10.1109/tmm.2021.3124083","title":"AutoMA: Towards Automatic Model Augmentation for Transferable Adversarial Attacks","display_name":"AutoMA: Towards Automatic Model Augmentation for Transferable Adversarial Attacks","publication_year":2021,"publication_date":"2021-11-02","ids":{"openalex":"https://openalex.org/W3208594240","doi":"https://doi.org/10.1109/tmm.2021.3124083","mag":"3208594240"},"language":"en","primary_location":{"id":"doi:10.1109/tmm.2021.3124083","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tmm.2021.3124083","pdf_url":null,"source":{"id":"https://openalex.org/S137030581","display_name":"IEEE Transactions on Multimedia","issn_l":"1520-9210","issn":["1520-9210","1941-0077"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Multimedia","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Haojie Yuan","orcid":"https://orcid.org/0000-0003-3027-3109"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Haojie Yuan","raw_affiliation_strings":["School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China"],"raw_orcid":"https://orcid.org/0000-0003-3027-3109","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045938154","display_name":"Qi Chu","orcid":"https://orcid.org/0000-0003-3028-0755"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qi Chu","raw_affiliation_strings":["School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China"],"raw_orcid":"https://orcid.org/0000-0003-3028-0755","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101854976","display_name":"Feng Zhu","orcid":"https://orcid.org/0000-0003-4309-170X"},"institutions":[{"id":"https://openalex.org/I4210128910","display_name":"Group Sense (China)","ror":"https://ror.org/036wd5777","country_code":"CN","type":"company","lineage":["https://openalex.org/I4210128910"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Feng Zhu","raw_affiliation_strings":["SenseTime Ltd., Shenzhen, China"],"raw_orcid":"https://orcid.org/0000-0003-4309-170X","affiliations":[{"raw_affiliation_string":"SenseTime Ltd., Shenzhen, China","institution_ids":["https://openalex.org/I4210128910"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078304976","display_name":"Rui Zhao","orcid":"https://orcid.org/0000-0003-4271-0206"},"institutions":[{"id":"https://openalex.org/I4210128910","display_name":"Group Sense (China)","ror":"https://ror.org/036wd5777","country_code":"CN","type":"company","lineage":["https://openalex.org/I4210128910"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Rui Zhao","raw_affiliation_strings":["SenseTime Ltd., Shenzhen, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"SenseTime Ltd., Shenzhen, China","institution_ids":["https://openalex.org/I4210128910"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100395493","display_name":"Bin Liu","orcid":"https://orcid.org/0000-0002-3977-8800"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Bin Liu","raw_affiliation_strings":["School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China"],"raw_orcid":"https://orcid.org/0000-0002-3977-8800","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5064573190","display_name":"Nenghai Yu","orcid":"https://orcid.org/0000-0003-4417-9316"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Nenghai Yu","raw_affiliation_strings":["School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China"],"raw_orcid":"https://orcid.org/0000-0003-4417-9316","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I126520041"],"apc_list":null,"apc_paid":null,"fwci":1.6797,"has_fulltext":false,"cited_by_count":21,"citation_normalized_percentile":{"value":0.87198221,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":"25","issue":null,"first_page":"203","last_page":"213"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9706000089645386,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9595000147819519,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8461927175521851},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.680962085723877},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.506452202796936},{"id":"https://openalex.org/keywords/transformation","display_name":"Transformation (genetics)","score":0.4696931838989258},{"id":"https://openalex.org/keywords/distortion","display_name":"Distortion (music)","score":0.43799111247062683},{"id":"https://openalex.org/keywords/differentiable-function","display_name":"Differentiable function","score":0.4364972412586212},{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.4214911460876465},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4087752103805542},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3318294286727905},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.0794217586517334}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8461927175521851},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.680962085723877},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.506452202796936},{"id":"https://openalex.org/C204241405","wikidata":"https://www.wikidata.org/wiki/Q461499","display_name":"Transformation (genetics)","level":3,"score":0.4696931838989258},{"id":"https://openalex.org/C126780896","wikidata":"https://www.wikidata.org/wiki/Q899871","display_name":"Distortion (music)","level":4,"score":0.43799111247062683},{"id":"https://openalex.org/C202615002","wikidata":"https://www.wikidata.org/wiki/Q783507","display_name":"Differentiable function","level":2,"score":0.4364972412586212},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.4214911460876465},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4087752103805542},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3318294286727905},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0794217586517334},{"id":"https://openalex.org/C2776257435","wikidata":"https://www.wikidata.org/wiki/Q1576430","display_name":"Bandwidth (computing)","level":2,"score":0.0},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C194257627","wikidata":"https://www.wikidata.org/wiki/Q211554","display_name":"Amplifier","level":3,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tmm.2021.3124083","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tmm.2021.3124083","pdf_url":null,"source":{"id":"https://openalex.org/S137030581","display_name":"IEEE Transactions on Multimedia","issn_l":"1520-9210","issn":["1520-9210","1941-0077"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Multimedia","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G175089312","display_name":null,"funder_award_id":"U20B2047","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8557816227","display_name":null,"funder_award_id":"62002336","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":60,"referenced_works":["https://openalex.org/W1686810756","https://openalex.org/W1903029394","https://openalex.org/W2064675550","https://openalex.org/W2108598243","https://openalex.org/W2155904486","https://openalex.org/W2183341477","https://openalex.org/W2194775991","https://openalex.org/W2279098554","https://openalex.org/W2302255633","https://openalex.org/W2412782625","https://openalex.org/W2533598788","https://openalex.org/W2549139847","https://openalex.org/W2620038827","https://openalex.org/W2736601468","https://openalex.org/W2774018344","https://openalex.org/W2774644650","https://openalex.org/W2783482415","https://openalex.org/W2896078964","https://openalex.org/W2903665338","https://openalex.org/W2904169782","https://openalex.org/W2947874337","https://openalex.org/W2949736877","https://openalex.org/W2962847335","https://openalex.org/W2962872506","https://openalex.org/W2963037989","https://openalex.org/W2963125010","https://openalex.org/W2963771536","https://openalex.org/W2963857521","https://openalex.org/W2963918968","https://openalex.org/W2964350391","https://openalex.org/W2969542116","https://openalex.org/W2984699060","https://openalex.org/W2997583194","https://openalex.org/W3003520923","https://openalex.org/W3034176567","https://openalex.org/W3035005405","https://openalex.org/W3035182590","https://openalex.org/W3035569111","https://openalex.org/W3046953693","https://openalex.org/W3100505241","https://openalex.org/W3106050153","https://openalex.org/W3119118477","https://openalex.org/W3161469108","https://openalex.org/W4297775537","https://openalex.org/W6620707391","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6640425456","https://openalex.org/W6683204974","https://openalex.org/W6695314431","https://openalex.org/W6731927902","https://openalex.org/W6737664043","https://openalex.org/W6741002519","https://openalex.org/W6746402973","https://openalex.org/W6747939174","https://openalex.org/W6761100157","https://openalex.org/W6767513282","https://openalex.org/W6768366551","https://openalex.org/W6772167297","https://openalex.org/W6783404350"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W4285226279","https://openalex.org/W4288019534"],"abstract_inverted_index":{"Recent":[0],"adversarial":[1,98],"attack":[2],"works":[3],"attempt":[4],"to":[5,89,119],"improve":[6],"the":[7,18,22,46,54,69,122,132,137,188],"transferability":[8],"by":[9,65,192],"applying":[10],"various":[11,109],"differentiable":[12,19],"transformations":[13,20,111,157,177],"on":[14,158],"input":[15],"images.":[16],"Considering":[17],"and":[21,115,170],"original":[23,48],"model":[24,36,55,72,93,150],"together":[25,130],"as":[26,35],"a":[27,91,103,203],"new":[28],"model,":[29],"these":[30,60],"methods":[31,61],"can":[32],"be":[33],"regarded":[34],"augmentation":[37,56,73,94,124,128,151,189],"that":[38,107,187],"effectively":[39],"derives":[40],"an":[41,75,83],"ensemble":[42],"of":[43,71,206],"models":[44],"from":[45],"single":[47],"model.":[49],"Despite":[50],"their":[51],"impressive":[52],"performance,":[53],"policies":[57,129,201],"used":[58],"in":[59,202],"are":[62,161],"manually":[63,199],"designed":[64,200],"experimental":[66],"attempts,":[67],"leaving":[68],"design":[70,102],"policy":[74,95,190],"open":[76],"question.":[77],"In":[78],"this":[79],"paper,":[80],"we":[81,101],"propose":[82],"Automatic":[84],"Model":[85],"Augmentation":[86,156],"(AutoMA)":[87],"approach":[88],"find":[90],"strong":[92,123],"for":[96,121,144,175,181],"transferable":[97],"attacks.":[99],"Specifically,":[100],"discrete":[104],"search":[105,120],"space":[106,160],"contains":[108],"diffierentiable":[110],"with":[112,131],"different":[113],"parameters":[114],"adopt":[116],"reinforcement":[117],"learning":[118],"policy.":[125],"The":[126,165],"sampled":[127],"rewards":[133],"they":[134],"obtain":[135],"during":[136],"searching":[138],"process":[139],"reveal":[140],"several":[141],"valuable":[142],"observations":[143],"designing":[145],"more":[146],"powerful":[147],"attacks":[148],"using":[149],"policy:":[152],"<italic":[153],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[154],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">1)":[155],"color":[159],"less":[162],"effective;":[163],"2)":[164],"transformation":[166],"type":[167],"diversity":[168],"matters;":[169],"3)":[171],"Using":[172],"small":[173],"distortion":[174,180],"geometric":[176],"while":[178],"larger":[179],"intensity":[182],"transformations.</i>":[183],"Extensive":[184],"experiments":[185],"show":[186],"found":[191],"AutoMA":[193],"achieves":[194],"superior":[195],"performance":[196],"than":[197],"existing":[198],"wide":[204],"range":[205],"cases.":[207]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":8},{"year":2024,"cited_by_count":6},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":1}],"updated_date":"2026-04-28T14:05:53.105641","created_date":"2025-10-10T00:00:00"}
