{"id":"https://openalex.org/W4387994756","doi":"https://doi.org/10.48550/arxiv.2310.17626","title":"A Survey on Transferability of Adversarial Examples across Deep Neural Networks","display_name":"A Survey on Transferability of Adversarial Examples across Deep Neural Networks","publication_year":2023,"publication_date":"2023-10-26","ids":{"openalex":"https://openalex.org/W4387994756","doi":"https://doi.org/10.48550/arxiv.2310.17626"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2310.17626","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2310.17626","pdf_url":"https://arxiv.org/pdf/2310.17626","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2310.17626","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5055994909","display_name":"Jindong Gu","orcid":"https://orcid.org/0009-0000-0574-0129"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Gu, Jindong","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084784341","display_name":"Xiaojun Jia","orcid":"https://orcid.org/0000-0002-2018-9344"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jia, Xiaojun","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5076408703","display_name":"Pau de Jorge","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"de Jorge, Pau","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101260231","display_name":"Wenqain Yu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yu, Wenqain","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100461515","display_name":"Xinwei Liu","orcid":"https://orcid.org/0000-0002-9829-3395"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Xinwei","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113802054","display_name":"Avery Ma","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ma, Avery","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":null,"display_name":"Xun, Yuan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xun, Yuan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112856691","display_name":"Anjun Hu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hu, Anjun","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009527804","display_name":"Ashkan Khakzar","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Khakzar, Ashkan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5104130738","display_name":"Zhijiang Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Zhijiang","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068837264","display_name":"Xiaochun Cao","orcid":"https://orcid.org/0000-0001-7141-708X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Cao, Xiaochun","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5109615038","display_name":"Philip Torr","orcid":"https://orcid.org/0000-0001-5545-7217"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Torr, Philip","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":12,"corresponding_author_ids":["https://openalex.org/A5055994909"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"cited_by_count":11,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.921295702457428},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.8474330306053162},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7185208797454834},{"id":"https://openalex.org/keywords/categorization","display_name":"Categorization","score":0.6628844738006592},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5844685435295105},{"id":"https://openalex.org/keywords/property","display_name":"Property (philosophy)","score":0.5560480952262878},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5501410365104675},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5435483455657959},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.48775750398635864},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.44128289818763733},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4121629595756531},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.15088817477226257},{"id":"https://openalex.org/keywords/epistemology","display_name":"Epistemology","score":0.1480315625667572}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.921295702457428},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.8474330306053162},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7185208797454834},{"id":"https://openalex.org/C94124525","wikidata":"https://www.wikidata.org/wiki/Q912550","display_name":"Categorization","level":2,"score":0.6628844738006592},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5844685435295105},{"id":"https://openalex.org/C189950617","wikidata":"https://www.wikidata.org/wiki/Q937228","display_name":"Property (philosophy)","level":2,"score":0.5560480952262878},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5501410365104675},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5435483455657959},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.48775750398635864},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.44128289818763733},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4121629595756531},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.15088817477226257},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.1480315625667572},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"pmh:oai:arXiv.org:2310.17626","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2310.17626","pdf_url":"https://arxiv.org/pdf/2310.17626","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},{"id":"pmh:oai:ora.ox.ac.uk:uuid:44baf078-e03e-4c2f-8c2e-cf54541a8d9d","is_oa":false,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4306402636","display_name":"Oxford University Research Archive (ORA) (University of Oxford)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I40120149","host_organization_name":"University of Oxford","host_organization_lineage":["https://openalex.org/I40120149"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Symplectic Elements","raw_type":"http://purl.org/coar/resource_type/c_dcae04bc"},{"id":"doi:10.48550/arxiv.2310.17626","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2310.17626","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2310.17626","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2310.17626","pdf_url":"https://arxiv.org/pdf/2310.17626","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},"sustainable_development_goals":[{"score":0.46000000834465027,"display_name":"Quality Education","id":"https://metadata.un.org/sdg/4"}],"awards":[{"id":"https://openalex.org/G1203979484","display_name":null,"funder_award_id":"EP/N019474/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"},{"id":"https://openalex.org/G2807882867","display_name":null,"funder_award_id":"EP/N019474/1","funder_id":"https://openalex.org/F4320333591","funder_display_name":"Multidisciplinary University Research Initiative"},{"id":"https://openalex.org/G2864483227","display_name":null,"funder_award_id":"Fellowship","funder_id":"https://openalex.org/F4320320005","funder_display_name":"Royal Academy of Engineering"},{"id":"https://openalex.org/G6505763180","display_name":null,"funder_award_id":"EP/W002981/1","funder_id":"https://openalex.org/F4320314731","funder_display_name":"UK Research and Innovation"}],"funders":[{"id":"https://openalex.org/F4320314731","display_name":"UK Research and Innovation","ror":"https://ror.org/001aqnf71"},{"id":"https://openalex.org/F4320320005","display_name":"Royal Academy of Engineering","ror":"https://ror.org/0526snb40"},{"id":"https://openalex.org/F4320333591","display_name":"Multidisciplinary University Research Initiative","ror":null},{"id":"https://openalex.org/F4320334627","display_name":"Engineering and Physical Sciences Research Council","ror":"https://ror.org/0439y7842"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4387994756.pdf","grobid_xml":"https://content.openalex.org/works/W4387994756.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4288055406","https://openalex.org/W4200630034","https://openalex.org/W3137894200","https://openalex.org/W3092178728","https://openalex.org/W4226402597","https://openalex.org/W3132910851","https://openalex.org/W4377864639","https://openalex.org/W4392340763","https://openalex.org/W4283325551","https://openalex.org/W2997056298"],"abstract_inverted_index":{"The":[0],"emergence":[1],"of":[2,15,63,69,99,108,112,135,162],"Deep":[3],"Neural":[4],"Networks":[5],"(DNNs)":[6],"has":[7,30],"revolutionized":[8],"various":[9],"domains":[10],"by":[11],"enabling":[12],"the":[13,67,94,100,106,109,125,132,160],"resolution":[14],"complex":[16],"tasks":[17,151],"spanning":[18],"image":[19,140],"recognition,":[20],"natural":[21],"language":[22],"processing,":[23],"and":[24,123,152,155],"scientific":[25],"problem-solving.":[26],"However,":[27],"this":[28,64],"progress":[29],"also":[31,143],"brought":[32],"to":[33,44,119,147],"light":[34],"a":[35,83],"concerning":[36],"vulnerability:":[37],"adversarial":[38,70,110,113,121,166],"examples.":[39,114],"These":[40],"crafted":[41,74],"inputs,":[42],"imperceptible":[43],"humans,":[45],"can":[46,78],"manipulate":[47],"machine":[48],"learning":[49],"models":[50],"into":[51],"making":[52],"erroneous":[53],"predictions,":[54],"raising":[55],"concerns":[56],"for":[57,75,96],"safety-critical":[58],"applications.":[59],"An":[60],"intriguing":[61,87],"property":[62,88],"phenomenon":[65],"is":[66],"transferability":[68,111,122],"examples,":[71],"where":[72],"perturbations":[73],"one":[76],"model":[77],"deceive":[79],"another,":[80],"often":[81],"with":[82],"different":[84],"architecture.":[85],"This":[86,103],"enables":[89],"black-box":[90],"attacks":[91],"which":[92],"circumvents":[93],"need":[95],"detailed":[97],"knowledge":[98],"target":[101],"model.":[102],"survey":[104],"explores":[105],"landscape":[107],"We":[115],"categorize":[116],"existing":[117],"methodologies":[118],"enhance":[120],"discuss":[124],"fundamental":[126],"principles":[127],"guiding":[128],"each":[129],"approach.":[130],"While":[131],"predominant":[133],"body":[134],"research":[136],"primarily":[137],"concentrates":[138],"on":[139],"classification,":[141],"we":[142],"extend":[144],"our":[145],"discussion":[146],"encompass":[148],"other":[149],"vision":[150],"beyond.":[153],"Challenges":[154],"opportunities":[156],"are":[157],"discussed,":[158],"highlighting":[159],"importance":[161],"fortifying":[163],"DNNs":[164],"against":[165],"vulnerabilities":[167],"in":[168],"an":[169],"evolving":[170],"landscape.":[171]},"counts_by_year":[{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":4}],"updated_date":"2026-04-17T18:11:37.981687","created_date":"2023-10-28T00:00:00"}
