{"id":"https://openalex.org/W7160323362","doi":"https://doi.org/10.48550/arxiv.2605.01098","title":"Almost for Free: Crafting Adversarial Examples with Convolutional Image Filters","display_name":"Almost for Free: Crafting Adversarial Examples with Convolutional Image Filters","publication_year":2026,"publication_date":"2026-05-01","ids":{"openalex":"https://openalex.org/W7160323362","doi":"https://doi.org/10.48550/arxiv.2605.01098"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.01098","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.01098","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.01098","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5135342287","display_name":"Alexander Warnecke","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Warnecke, Alexander","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5066077721","display_name":"Konrad Rieck","orcid":"https://orcid.org/0000-0002-5054-8758"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Rieck, Konrad","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.974399983882904,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.974399983882904,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.006800000090152025,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.003700000001117587,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8468000292778015},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.6051999926567078},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.597599983215332},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.5485000014305115},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.46309998631477356},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.45210000872612},{"id":"https://openalex.org/keywords/fragility","display_name":"Fragility","score":0.4212000072002411},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.4092999994754791},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.40849998593330383}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8468000292778015},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7445999979972839},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6389999985694885},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.6051999926567078},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.597599983215332},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.5485000014305115},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4975999891757965},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.46309998631477356},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.45210000872612},{"id":"https://openalex.org/C80191262","wikidata":"https://www.wikidata.org/wiki/Q5477668","display_name":"Fragility","level":2,"score":0.4212000072002411},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.4092999994754791},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.40849998593330383},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3874000012874603},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.3792000114917755},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.3695000112056732},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.36169999837875366},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.35749998688697815},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.30570000410079956},{"id":"https://openalex.org/C45347329","wikidata":"https://www.wikidata.org/wiki/Q5166604","display_name":"Convolution (computer science)","level":3,"score":0.30410000681877136},{"id":"https://openalex.org/C2779757391","wikidata":"https://www.wikidata.org/wiki/Q6002292","display_name":"Image translation","level":3,"score":0.2897999882698059},{"id":"https://openalex.org/C2777655017","wikidata":"https://www.wikidata.org/wiki/Q1501161","display_name":"Toolbox","level":2,"score":0.28790000081062317},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.2874999940395355},{"id":"https://openalex.org/C9417928","wikidata":"https://www.wikidata.org/wiki/Q1070689","display_name":"Image processing","level":3,"score":0.27720001339912415},{"id":"https://openalex.org/C2776151529","wikidata":"https://www.wikidata.org/wiki/Q3045304","display_name":"Object detection","level":3,"score":0.2667999863624573},{"id":"https://openalex.org/C106131492","wikidata":"https://www.wikidata.org/wiki/Q3072260","display_name":"Filter (signal processing)","level":2,"score":0.26159998774528503},{"id":"https://openalex.org/C157657479","wikidata":"https://www.wikidata.org/wiki/Q2367247","display_name":"Closed captioning","level":3,"score":0.25999999046325684},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.2547000050544739}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.01098","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.01098","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.01098","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.01098","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Adversarial":[0],"examples":[1],"in":[2,122],"machine":[3,43],"learning":[4,64],"are":[5,53,70],"typically":[6],"generated":[7],"using":[8,103],"gradients,":[9],"obtained":[10],"either":[11],"directly":[12],"through":[13],"access":[14],"to":[15,22,33,62,100,149,167],"the":[16,79,112,129,132,159],"model":[17],"or":[18],"approximated":[19],"via":[20],"queries":[21],"it.":[23],"In":[24,45],"this":[25],"paper,":[26],"we":[27,47,82,110,135],"propose":[28],"a":[29,75,123,141],"much":[30],"simpler":[31],"approach":[32],"craft":[34],"adversarial":[35,108],"examples,":[36,109],"drawing":[37],"inspiration":[38],"from":[39],"insights":[40,157],"of":[41,114,119,131,161],"explainable":[42],"learning.":[44],"particular,":[46],"design":[48],"\\emph{adversarial":[49],"image":[50,151],"filters}":[51],"that":[52,84],"based":[54],"on":[55,95],"classic":[56,150],"edge":[57],"detection":[58],"algorithms":[59],"but":[60],"optimized":[61],"deceive":[63],"models.":[65],"The":[66],"resulting":[67,121],"untargeted":[68],"attacks":[69],"transferable":[71],"and":[72,93,146,164],"require":[73],"only":[74],"single":[76],"pass":[77],"over":[78],"input.":[80],"Empirically,":[81],"find":[83],"3x3":[85],"filters":[86],"already":[87],"enable":[88],"success":[89],"rates":[90],"between":[91,144],"30%":[92],"80%":[94],"different":[96],"neural":[97,162],"networks.":[98],"Compared":[99],"related":[101],"approaches":[102],"generative":[104],"models":[105,145],"for":[106],"crafting":[107],"reduce":[111],"number":[113],"parameters":[115,130],"by":[116],"five":[117],"orders":[118],"magnitude,":[120],"very":[124],"efficient":[125],"attack.":[126],"When":[127],"investigating":[128],"learned":[133],"filters,":[134],"observe":[136],"interesting":[137],"properties":[138],"such":[139],"as":[140],"high":[142],"transferability":[143],"structures":[147],"common":[148],"filters.":[152],"Our":[153],"results":[154],"provide":[155],"further":[156],"into":[158],"vulnerability":[160],"networks":[163],"their":[165],"fragility":[166],"malicious":[168],"noise.":[169]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-06T00:00:00"}
