{"id":"https://openalex.org/W4410609173","doi":"https://doi.org/10.1109/satml64287.2025.00049","title":"Reliable Evaluation of Adversarial Transferability","display_name":"Reliable Evaluation of Adversarial Transferability","publication_year":2025,"publication_date":"2025-04-09","ids":{"openalex":"https://openalex.org/W4410609173","doi":"https://doi.org/10.1109/satml64287.2025.00049"},"language":"en","primary_location":{"id":"doi:10.1109/satml64287.2025.00049","is_oa":false,"landing_page_url":"https://doi.org/10.1109/satml64287.2025.00049","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5113971970","display_name":"Wenqian Yu","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Wenqian Yu","raw_affiliation_strings":["School of Information Management, Wuhan University,Wuhan,China"],"affiliations":[{"raw_affiliation_string":"School of Information Management, Wuhan University,Wuhan,China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5055994909","display_name":"Jindong Gu","orcid":"https://orcid.org/0009-0000-0574-0129"},"institutions":[{"id":"https://openalex.org/I4210146410","display_name":"Science Oxford","ror":"https://ror.org/04j8yhy50","country_code":"GB","type":"nonprofit","lineage":["https://openalex.org/I4210146410"]},{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Jindong Gu","raw_affiliation_strings":["University of Oxford,Department of Engineering Science,Oxford,United Kingdom"],"affiliations":[{"raw_affiliation_string":"University of Oxford,Department of Engineering Science,Oxford,United Kingdom","institution_ids":["https://openalex.org/I4210146410","https://openalex.org/I40120149"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5061369238","display_name":"Zhijiang Li","orcid":"https://orcid.org/0000-0001-9712-2220"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhijiang Li","raw_affiliation_strings":["School of Information Management, Wuhan University,Wuhan,China"],"affiliations":[{"raw_affiliation_string":"School of Information Management, Wuhan University,Wuhan,China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5001534492","display_name":"Philip H. S. Torr","orcid":null},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]},{"id":"https://openalex.org/I4210146410","display_name":"Science Oxford","ror":"https://ror.org/04j8yhy50","country_code":"GB","type":"nonprofit","lineage":["https://openalex.org/I4210146410"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Philip Torr","raw_affiliation_strings":["University of Oxford,Department of Engineering Science,Oxford,United Kingdom"],"affiliations":[{"raw_affiliation_string":"University of Oxford,Department of Engineering Science,Oxford,United Kingdom","institution_ids":["https://openalex.org/I4210146410","https://openalex.org/I40120149"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5113971970"],"corresponding_institution_ids":["https://openalex.org/I37461747"],"apc_list":null,"apc_paid":null,"fwci":2.8414,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.90885405,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"797","last_page":"810"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.97079998254776,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.97079998254776,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.9309839010238647},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8960875868797302},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.634462833404541},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3346865177154541},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.21029126644134521}],"concepts":[{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.9309839010238647},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8960875868797302},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.634462833404541},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3346865177154541},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.21029126644134521},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/satml64287.2025.00049","is_oa":false,"landing_page_url":"https://doi.org/10.1109/satml64287.2025.00049","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":76,"referenced_works":["https://openalex.org/W1570411240","https://openalex.org/W1990221069","https://openalex.org/W2108598243","https://openalex.org/W2112796928","https://openalex.org/W2194775991","https://openalex.org/W2295038166","https://openalex.org/W2762664271","https://openalex.org/W2774644650","https://openalex.org/W2775079417","https://openalex.org/W2792432942","https://openalex.org/W2798878556","https://openalex.org/W2896078964","https://openalex.org/W2947874337","https://openalex.org/W2962847335","https://openalex.org/W2963446712","https://openalex.org/W2969542116","https://openalex.org/W2984699060","https://openalex.org/W2991496458","https://openalex.org/W2997583194","https://openalex.org/W3006966652","https://openalex.org/W3034302278","https://openalex.org/W3035569111","https://openalex.org/W3041992316","https://openalex.org/W3096831136","https://openalex.org/W3106050153","https://openalex.org/W3108534877","https://openalex.org/W3127807678","https://openalex.org/W3138516171","https://openalex.org/W3143373604","https://openalex.org/W3171288285","https://openalex.org/W3177184533","https://openalex.org/W3179647175","https://openalex.org/W3180095048","https://openalex.org/W3186991201","https://openalex.org/W3196621661","https://openalex.org/W3202090809","https://openalex.org/W3204647170","https://openalex.org/W3214186397","https://openalex.org/W3217804443","https://openalex.org/W4226378932","https://openalex.org/W4246193833","https://openalex.org/W4283797276","https://openalex.org/W4312423415","https://openalex.org/W4312697129","https://openalex.org/W4312790346","https://openalex.org/W4312810288","https://openalex.org/W4313141826","https://openalex.org/W4313182999","https://openalex.org/W4319300575","https://openalex.org/W4382464557","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6640425456","https://openalex.org/W6731927902","https://openalex.org/W6734194636","https://openalex.org/W6739868092","https://openalex.org/W6761372651","https://openalex.org/W6768366551","https://openalex.org/W6771961379","https://openalex.org/W6773713311","https://openalex.org/W6776690448","https://openalex.org/W6784025586","https://openalex.org/W6784233108","https://openalex.org/W6785111489","https://openalex.org/W6787052717","https://openalex.org/W6788135285","https://openalex.org/W6790022663","https://openalex.org/W6796421320","https://openalex.org/W6797592835","https://openalex.org/W6800992949","https://openalex.org/W6802545238","https://openalex.org/W6838329916","https://openalex.org/W6838510352","https://openalex.org/W6845892164","https://openalex.org/W6850063601","https://openalex.org/W6851530655"],"related_works":["https://openalex.org/W4288055406","https://openalex.org/W4200630034","https://openalex.org/W3137894200","https://openalex.org/W3092178728","https://openalex.org/W4226402597","https://openalex.org/W3132910851","https://openalex.org/W4377864639","https://openalex.org/W4409346678","https://openalex.org/W4392340763","https://openalex.org/W4283325551"],"abstract_inverted_index":{"Adversarial":[0],"examples":[1],"(AEs)":[2],"with":[3],"small":[4],"adversarial":[5,61,124],"perturbations":[6],"can":[7,22,141],"mislead":[8],"deep":[9],"neural":[10,112],"networks":[11],"(DNNs)":[12],"into":[13],"wrong":[14],"predictions.":[15],"The":[16,148],"AEs":[17,35],"created":[18],"on":[19,104,162],"one":[20],"DNN":[21],"also":[23],"fool":[24],"other":[25],"networks.":[26,113],"Over":[27],"the":[28,32,116,123],"last":[29],"few":[30],"years,":[31],"transferability":[33,59,125,149],"of":[34,60,111,151],"has":[36],"garnered":[37],"significant":[38],"attention":[39],"as":[40,71],"it":[41,57],"is":[42,68,131,136],"a":[43,167],"crucial":[44],"property":[45],"for":[46],"facilitating":[47],"black-box":[48],"attacks.":[49],"Many":[50],"approaches":[51],"have":[52],"been":[53],"proposed":[54],"to":[55,115,144,178],"improve":[56],"and":[58,134,187],"attacks":[62],"across":[63,126],"Convolutional":[64],"Neural":[65],"Networks":[66],"(CNNs)":[67],"remarkably":[69],"high,":[70],"attested":[72],"by":[73],"previous":[74,152],"research.":[75],"However,":[76],"such":[77],"evaluation":[78,172,188],"methods":[79,100,154],"are":[80],"not":[81],"reliable":[82,168],"since":[83],"all":[84,145],"CNNs":[85],"share":[86],"some":[87],"similar":[88],"architectural":[89],"biases.":[90],"In":[91],"this":[92],"work,":[93],"we":[94,102,165],"re-evaluate":[95],"13":[96],"representative":[97],"transferability-enhancing":[98],"attack":[99],"where":[101],"test":[103],"18":[105],"popular":[106,146],"models":[107],"from":[108],"4":[109],"types":[110,130],"Contrary":[114],"prevailing":[117],"belief,":[118],"our":[119,158,163,176],"reevaluation":[120],"revealed":[121],"that":[122,140],"these":[127],"diverse":[128],"network":[129],"notably":[132],"diminished,":[133],"there":[135],"no":[137],"single":[138],"AE":[139],"be":[142],"transferred":[143],"models.":[147],"rank":[150],"attacking":[153],"changes":[155],"when":[156],"under":[157],"comprehensive":[159],"evaluation.":[160],"Based":[161],"analysis,":[164],"propose":[166],"benchmark":[169,177],"including":[170],"three":[171],"protocols.":[173,189],"We":[174],"release":[175],"facilitate":[179],"future":[180],"research,":[181],"which":[182],"includes":[183],"code,":[184],"model":[185],"checkpoints,":[186]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
