Transferability Bound Theory: Exploring Relationship between Adversarial Transferability and Flatness
Mingyuan Fan, Xiaodan Li, Cen Chen, Wenmeng Zhou, Yaliang Li
Abstract
A prevailing belief in attack and defense community is that the higher flatness of adversarial examples enables their better cross-model transferability, leading to a growing interest in employing sharpness-aware minimization and its variants. However, the theoretical relationship between the transferability of adversarial examples and their flatness has not been well established, making the belief questionable. To bridge this gap, we embark on a theoretical investigation and, for the first time, derive a theoretical bound for the transferability of adversarial examples with few practical assumptions. Our analysis challenges this belief by demonstrating that the increased flatness of adversarial examples does not necessarily guarantee improved transferability. Moreover, building upon the theoretical analysis, we propose TPA, a Theoretically Provable Attack that optimizes a surrogate of the derived bound to craft adversarial examples. Extensive experiments across widely used benchmark datasets and various real-world applications show that TPA can craft more transferable adversarial examples compared to state-of-the-art baselines. We hope that these results can recalibrate preconceived impressions within the community and facilitate the development of stronger adversarial attack and defense mechanisms. The source codes are available in.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 995a9eee-d200-4d9b-a5da-6826a3f674b0Cited by top-tier papers4
- Boosting Adversarial Transferability via Residual Perturbation AttackJinjia Peng, Zeze Tao, Huibing Wang, Meng Wang et al.ICCV 2025 · 2 citations
- Boosting Adversarial Transferability via Negative Hessian Trace RegularizationYunfei Long, Zilin Tian, Liguo Zhang, Huosheng XuICCV 2025 · 1 citation
- Understanding Model Ensemble in Transferable Adversarial AttackWei Yao, Zeliang Zhang, Huayi Tang, Yong LiuICML 2025
- Prompting Adversarial Transferability via Path Flatness AttackZeze Tao, Jinjia Peng, Huibing WangAAAI 2026
Builds on26
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Sharpness-aware Minimization for Efficiently Improving GeneralizationPierre Foret, Ariel Kleiner, Hossein Mobahi, Behnam NeyshaburICLR 2021 · 1,861 citations
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNetsDongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey et al.ICLR 2020 · 357 citations
- Admix: Enhancing the Transferability of Adversarial AttacksXiaosen Wang, Xuanran He, Jingdong Wang, Kun HeICCV 2021 · 282 citations
Related papers
- A Theory of Transfer-Based Black-Box Attacks: Explanation and ImplicationsYanbo Chen, Weiwei LiuNeurIPS 2023 · 22 citations
- Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial TransferabilityYechao Zhang, Shengshan Hu, Leo Yu Zhang, Junyu Shi et al.S&P 2024 · 36 citations
- I-C Attack: In-place and Cross-pixel Augmentations for Highly Transferable Transformation-based AttacksJiaming Liang, Chi-Man PunACM MM 2025 · 3 citations
- Uncovering the Connections Between Adversarial Transferability and Knowledge TransferabilityKaizhao Liang, Jacky Y. Zhang, Boxin Wang, Zhuolin Yang et al.ICML 2021 · 33 citations
- Boosting Adversarial Transferability by Achieving Flat Local MaximaZhijin Ge, Xiaosen Wang, Hongying Liu, Fanhua Shang et al.NeurIPS 2023 · 112 citations
