{"id":"https://openalex.org/W4285606912","doi":"https://doi.org/10.24963/ijcai.2022/227","title":"Improving Transferability of Adversarial Examples with Virtual Step and Auxiliary Gradients","display_name":"Improving Transferability of Adversarial Examples with Virtual Step and Auxiliary Gradients","publication_year":2022,"publication_date":"2022-07-01","ids":{"openalex":"https://openalex.org/W4285606912","doi":"https://doi.org/10.24963/ijcai.2022/227"},"language":"en","primary_location":{"id":"doi:10.24963/ijcai.2022/227","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2022/227","pdf_url":"https://www.ijcai.org/proceedings/2022/0227.pdf","source":{"id":"https://openalex.org/S4363608755","display_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://www.ijcai.org/proceedings/2022/0227.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100447258","display_name":"Ming Zhang","orcid":"https://orcid.org/0000-0002-3441-7811"},"institutions":[{"id":"https://openalex.org/I114017466","display_name":"University of Technology Sydney","ror":"https://ror.org/03f0f6041","country_code":"AU","type":"education","lineage":["https://openalex.org/I114017466"]},{"id":"https://openalex.org/I125839683","display_name":"Beijing Institute of Technology","ror":"https://ror.org/01skt4w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I125839683","https://openalex.org/I890469752"]}],"countries":["AU","CN"],"is_corresponding":false,"raw_author_name":"Ming Zhang","raw_affiliation_strings":["National Key Laboratory of Science and Technology on Information System Security, Beijing, China","Data Science Lab, University of Technology Sydney; Deepblue Academy of Sciences; School of Computer Science and Technology, Beijing Institute of Technology"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Key Laboratory of Science and Technology on Information System Security, Beijing, China","institution_ids":[]},{"raw_affiliation_string":"Data Science Lab, University of Technology Sydney; Deepblue Academy of Sciences; School of Computer Science and Technology, Beijing Institute of Technology","institution_ids":["https://openalex.org/I114017466","https://openalex.org/I125839683"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053431750","display_name":"Xiaohui Kuang","orcid":"https://orcid.org/0000-0003-3816-402X"},"institutions":[{"id":"https://openalex.org/I116953780","display_name":"Tongji University","ror":"https://ror.org/03rc6as71","country_code":"CN","type":"education","lineage":["https://openalex.org/I116953780"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaohui Kuang","raw_affiliation_strings":["National Key Laboratory of Science and Technology on Information System Security, Beijing, China","College of Electronic and Information Engineering, Tongji University; Deepblue Academy of Sciences"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Key Laboratory of Science and Technology on Information System Security, Beijing, China","institution_ids":[]},{"raw_affiliation_string":"College of Electronic and Information Engineering, Tongji University; Deepblue Academy of Sciences","institution_ids":["https://openalex.org/I116953780"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100444617","display_name":"Li Hu","orcid":"https://orcid.org/0009-0007-9849-0800"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hu Li","raw_affiliation_strings":["National Key Laboratory of Science and Technology on Information System Security, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Key Laboratory of Science and Technology on Information System Security, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100738665","display_name":"Zhendong Wu","orcid":"https://orcid.org/0000-0002-1870-9558"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhendong Wu","raw_affiliation_strings":["National Key Laboratory of Science and Technology on Information System Security, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Key Laboratory of Science and Technology on Information System Security, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034893521","display_name":"Yuanping Nie","orcid":"https://orcid.org/0000-0002-8351-4108"},"institutions":[{"id":"https://openalex.org/I4210095297","display_name":"MIT University","ror":"https://ror.org/00v140q16","country_code":"MK","type":"education","lineage":["https://openalex.org/I4210095297"]},{"id":"https://openalex.org/I82951845","display_name":"RMIT University","ror":"https://ror.org/04ttjf776","country_code":"AU","type":"education","lineage":["https://openalex.org/I82951845"]}],"countries":["AU","MK"],"is_corresponding":false,"raw_author_name":"Yuanping Nie","raw_affiliation_strings":["National Key Laboratory of Science and Technology on Information System Security, Beijing, China","School of Computing Technologies, RMIT University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Key Laboratory of Science and Technology on Information System Security, Beijing, China","institution_ids":[]},{"raw_affiliation_string":"School of Computing Technologies, RMIT University","institution_ids":["https://openalex.org/I4210095297","https://openalex.org/I82951845"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5046444692","display_name":"Gang Zhao","orcid":"https://orcid.org/0000-0002-8980-945X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Gang Zhao","raw_affiliation_strings":["National Key Laboratory of Science and Technology on Information System Security, Beijing, China","Deepblue Academy of Sciences"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Key Laboratory of Science and Technology on Information System Security, Beijing, China","institution_ids":[]},{"raw_affiliation_string":"Deepblue Academy of Sciences","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.6229,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.67018288,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1629","last_page":"1635"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9768999814987183,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10645","display_name":"Cardiac Arrest and Resuscitation","score":0.9448000192642212,"subfield":{"id":"https://openalex.org/subfields/2711","display_name":"Emergency Medicine"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.8973590135574341},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8466174602508545},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8323041200637817},{"id":"https://openalex.org/keywords/margin","display_name":"Margin (machine learning)","score":0.6432430744171143},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.5116294026374817},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.47072187066078186},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.46439534425735474},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.4521118700504303},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.3836600184440613},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.337099552154541},{"id":"https://openalex.org/keywords/computer-engineering","display_name":"Computer engineering","score":0.3342137336730957},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.33313700556755066},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.32505255937576294},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.10661405324935913}],"concepts":[{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.8973590135574341},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8466174602508545},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8323041200637817},{"id":"https://openalex.org/C774472","wikidata":"https://www.wikidata.org/wiki/Q6760393","display_name":"Margin (machine learning)","level":2,"score":0.6432430744171143},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.5116294026374817},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.47072187066078186},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.46439534425735474},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.4521118700504303},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.3836600184440613},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.337099552154541},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.3342137336730957},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.33313700556755066},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.32505255937576294},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.10661405324935913},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.24963/ijcai.2022/227","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2022/227","pdf_url":"https://www.ijcai.org/proceedings/2022/0227.pdf","source":{"id":"https://openalex.org/S4363608755","display_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.24963/ijcai.2022/227","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2022/227","pdf_url":"https://www.ijcai.org/proceedings/2022/0227.pdf","source":{"id":"https://openalex.org/S4363608755","display_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4285606912.pdf","grobid_xml":"https://content.openalex.org/works/W4285606912.grobid-xml"},"referenced_works_count":23,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W2183341477","https://openalex.org/W2293768274","https://openalex.org/W2302255633","https://openalex.org/W2531409750","https://openalex.org/W2774018344","https://openalex.org/W2962700793","https://openalex.org/W2962847335","https://openalex.org/W2962872506","https://openalex.org/W2963001136","https://openalex.org/W2963070423","https://openalex.org/W2963542245","https://openalex.org/W2963744840","https://openalex.org/W2963920068","https://openalex.org/W2964350391","https://openalex.org/W2969542116","https://openalex.org/W2977099891","https://openalex.org/W2997583194","https://openalex.org/W3015625436","https://openalex.org/W3211999566","https://openalex.org/W4293846201"],"related_works":["https://openalex.org/W4288055406","https://openalex.org/W4200630034","https://openalex.org/W3137894200","https://openalex.org/W3092178728","https://openalex.org/W4226402597","https://openalex.org/W3132910851","https://openalex.org/W4377864639","https://openalex.org/W4392340763","https://openalex.org/W4283325551","https://openalex.org/W2997056298"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2,14],"have":[3],"been":[4],"demonstrated":[5],"to":[6,9,19,46,68,88,94,105,109,144],"be":[7,121],"vulnerable":[8],"adversarial":[10,51,76,111,135],"examples,":[11],"which":[12],"fool":[13],"by":[15,138,160],"adding":[16],"human-imperceptible":[17],"perturbations":[18,77],"benign":[20],"examples.":[21],"At":[22],"present,":[23],"the":[24,48,54,64,80,84,95,134,153,157],"practical":[25],"transfer-based":[26,36],"black-box":[27],"attacks":[28,37],"are":[29],"attracting":[30],"significant":[31],"attention.":[32],"However,":[33],"most":[34],"existing":[35,125],"achieve":[38],"only":[39,78,91],"relatively":[40],"limited":[41],"success":[42,158],"rates.":[43],"We":[44],"propose":[45],"improve":[47],"transferability":[49],"of":[50,56,164],"examples":[52,136],"through":[53],"use":[55],"a":[57,161],"virtual":[58,115],"step":[59,72,116],"and":[60,74,117],"auxiliary":[61,118],"gradients.":[62],"Here,":[63],"\u201cvirtual":[65],"step\u201d":[66],"refers":[67],"using":[69,89],"an":[70],"unusual":[71],"size":[73],"clipping":[75],"in":[79],"last":[81],"iteration,":[82],"while":[83],"\u201cauxiliary":[85],"gradients\u201d":[86],"refer":[87],"not":[90],"gradients":[92,103,119],"corresponding":[93,104],"ground-truth":[96],"label":[97],"(for":[98],"untargeted":[99],"attacks),":[100],"but":[101],"also":[102],"some":[106],"other":[107],"labels":[108],"generate":[110],"perturbations.":[112],"Our":[113,166],"proposed":[114],"can":[120,141],"easily":[122],"integrated":[123],"into":[124],"gradient-based":[126],"attacks.":[127],"Extensive":[128],"experiments":[129],"on":[130],"ImageNet":[131],"show":[132],"that":[133],"crafted":[137],"our":[139,150],"method":[140,151],"effectively":[142],"transfer":[143],"different":[145],"networks.":[146],"For":[147],"single-model":[148],"attacks,":[149],"outperforms":[152],"state-of-the-art":[154],"baselines,":[155],"improving":[156],"rates":[159],"large":[162],"margin":[163],"12%~28%.":[165],"code":[167],"is":[168],"publicly":[169],"available":[170],"at":[171],"https://github.com/mingcheung/Virtual-Step-and-Auxiliary-Gradients.":[172]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":3}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
