Understanding Model Ensemble in Transferable Adversarial Attack
Wei Yao, Zeliang Zhang, Huayi Tang, Yong Liu
Abstract
Model ensemble adversarial attack has become a powerful method for generating transferable adversarial examples that can target even unknown models, but its theoretical foundation remains underexplored. To address this gap, we provide early theoretical insights that serve as a roadmap for advancing model ensemble adversarial attack. We first define transferability error to measure the error in adversarial transferability, alongside concepts of diversity and empirical model ensemble Rademacher complexity. We then decompose the transferability error into vulnerability, diversity, and a constant, which rigidly explains the origin of transferability error in model ensemble attack: the vulnerability of an adversarial example to ensemble components, and the diversity of ensemble components. Furthermore, we apply the latest mathematical tools in information theory to bound the transferability error using complexity and generalization terms, validating three practical guidelines for reducing transferability error: (1) incorporating more surrogate models, (2) increasing their diversity, and (3) reducing their complexity in cases of overfitting. Finally, extensive experiments with 54 models validate our theoretical framework, representing a significant step forward in understanding transferable model ensemble adversarial attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 303654d2-e0ec-4f9d-8a5a-120ead1ad9f3Cited by top-tier papers4
- Transferable and Stealthy Adversarial Attacks on Large Vision-Language ModelsZhewen Yao, Yao Zhu, Shiliang ZhangICLR 2026 · 2 citations
- Out of Sight, Out of Track: Adversarial Attacks on Propagation-based Multi-Object Trackers via Query State ManipulationHalima Bouzidi, Haoyu Liu, Yonatan Achamyeleh, Praneetsai Iddamsetty et al.CVPR 2026 · 1 citation
- Training Robust Ensembles Requires Rethinking Lipschitz ContinuityAli Ebrahimpour Boroojeny, Hari Sundaram, Varun ChandrasekaranICLR 2025
- Rethinking Audio-Visual Adversarial Vulnerability from Temporal and Modality PerspectivesZeliang Zhang, Susan Liang, Daiki Shimada, Chenliang XuICLR 2025
Builds on27
- Deep Double Descent: Where Bigger Models and More Data HurtPreetum Nakkiran, Gal Kaplun, Yamini Bansal, Tristan Yang et al.ICLR 2020 · 1,108 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Visformer: The Vision-friendly TransformerZhengsu Chen, Lingxi Xie, Jianwei Niu, Xuefeng Liu et al.ICCV 2021 · 293 citations
- INSIDE: LLMs' Internal States Retain the Power of Hallucination DetectionChao Chen, Kai Liu, Ze Chen, Yi Gu et al.ICLR 2024 · 281 citations
Related papers
- Enhancing Adversarial Transferability with Checkpoints of a Single Model's TrainingShixin Li, Chaoxiang He, Xiaojing Ma, Bin Benjamin Zhu et al.CVPR 2025
- Rethinking Model Ensemble in Transfer-based Adversarial AttacksHuanran Chen, Yichi Zhang, Yinpeng Dong, Xiao Yang et al.ICLR 2024 · 112 citations
- DVERGE: Diversifying Vulnerabilities for Enhanced Robust Generation of EnsemblesHuanrui Yang, Jingyang Zhang, Hongliang Dong, Nathan Inkawhich et al.NeurIPS 2020 · 144 citations
- Ensemble Diversity Facilitates Adversarial TransferabilityBowen Tang, Zheng Wang, Yi Bin, Qi Dou et al.CVPR 2024 · 22 citations
- How to choose your best allies for a transferable attack?Thibault Maho, Seyed-Mohsen Moosavi-Dezfooli, Teddy FuronICCV 2023 · 1 citation
