Transfer Attacks Revisited: A Large-Scale Empirical Study in Real Computer Vision Settings
Yuhao Mao, Chong Fu, Saizhuo Wang, Shouling Ji, Xuhong Zhang, Zhenguang Liu, Jun Zhou, Alex X. Liu, Raheem Beyah, Ting Wang
Abstract
One intriguing property of adversarial attacks is their “transferability” – an adversarial example crafted with respect to one deep neural network (DNN) model is often found effective against other DNNs as well. Intensive research has been conducted on this phenomenon under simplistic controlled conditions. Yet, thus far there is still a lack of comprehensive understanding about transferability-based attacks (“transfer attacks”) in real-world environments.To bridge this critical gap, we conduct the first large-scale systematic empirical study of transfer attacks against major cloud-based MLaaS platforms, taking the components of a real transfer attack into account. The study leads to a number of interesting findings which are inconsistent to the existing ones, including: (i) Simple surrogates do not necessarily improve real transfer attacks. (ii) No dominant surrogate architecture is found in real transfer attacks. (iii) It is the gap between posterior (output of the softmax layer) rather than the gap between logit (so-called κ value) that increases transferability. Moreover, by comparing with prior works, we demonstrate that transfer attacks possess many previously unknown properties in real-world environments, such as (i) Model similarity is not a well-defined concept. (ii) L2 norm of perturbation can generate high transferability without usage of gradient and is a more powerful source than L∞ norm. We believe this work sheds light on the vulnerabilities of popular MLaaS platforms and points to a few promising research directions.1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 31830544-2df6-438b-b30b-8a6686cbe8c6Cited by top-tier papers9
- Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial TransferabilityYechao Zhang, Shengshan Hu, Leo Yu Zhang, Junyu Shi et al.S&P 2024 · 36 citations
- "Is your explanation stable?": A Robustness Evaluation Framework for Feature AttributionYuyou Gan, Yuhao Mao, Xuhong Zhang, Shouling Ji et al.CCS 2022 · 13 citations
- Efficient Query-Based Attack against ML-Based Android Malware Detection under Zero Knowledge SettingPing He, Yifan Xia, Xuhong Zhang, Shouling JiCCS 2023 · 13 citations
- Test-Time Poisoning Attacks Against Test-Time Adaptation ModelsTianshuo Cong, Xinlei He, Yun Shen, Yang ZhangS&P 2024 · 11 citations
- On the Robustness of Distributed Machine Learning Against Transfer AttacksSébastien Andreina, Pascal Zimmer, Ghassan KarameAAAI 2025 · 1 citation
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning AttacksAmbra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski et al.USENIX Security 2019 · 466 citations
- DEEPSEC: A Uniform Platform for Security Analysis of Deep Learning ModelXiang Ling, Shouling Ji, Jiaxu Zou, Jiannan Wang et al.S&P 2019 · 147 citations
- Backdoor Pre-trained Models Can Transfer to AllLujia Shen, Shouling Ji, Xuhong Zhang, Jinfeng Li et al.CCS 2021 · 72 citations
- Seeing is Living? Rethinking the Security of Facial Liveness Verification in the Deepfake EraChangjiang Li, Li Wang, Shouling Ji, Xuhong Zhang et al.USENIX Security 2022
Related papers
- Boosting the Transferability of Adversarial Attacks with Reverse Adversarial PerturbationZeyu Qin, Yanbo Fan, Yi Liu, Li Shen et al.NeurIPS 2022 · 135 citations
- Learning to Learn Transferable AttackShuman Fang, Jie Li, Xianming Lin, Rongrong JiAAAI 2022 · 26 citations
- Learning Transferable Adversarial PerturbationsKrishna Kanth Nakka, Mathieu SalzmannNeurIPS 2021 · 75 citations
- Making Substitute Models More Bayesian Can Enhance Transferability of Adversarial ExamplesQizhang Li, Yiwen Guo, Wangmeng Zuo, Hao ChenICLR 2023 · 5 citations
- CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial ExamplesHonggang Yu, Kaichen Yang, Teng Zhang, Yun-Yun Tsai et al.NDSS 2020
