Enhancing Adversarial Transferability with Checkpoints of a Single Model's Training
Shixin Li, Chaoxiang He, Xiaojing Ma, Bin Benjamin Zhu, Shuo Wang, Hongsheng Hu, Dongmei Zhang, Linchen Yu
Abstract
Adversarial attacks threaten the integrity of deep neural networks (DNNs), particularly in high-stakes applications. In this paper, we present a novel black-box adversarial attack that leverages the diverse checkpoints generated during a single model's training trajectory. Unlike conventional ensemble attacks that require multiple surrogate models with diverse architectures, our approach exploits the intrinsic diversity captured over different training stages of a single surrogate model. By decomposing the learned representations into task-intrinsic and task-irrelevant components, we employ an accuracy gap-based selection strategy to identify checkpoints that predominantly capture transferable, task-intrinsic knowledge. Extensive experiments on ImageNet and CIFAR-10 demonstrate that our method consistently outperforms traditional ensemble attacks in terms of transferability, even under resource-constrained and practical settings. This work offers a resource-efficient solution for crafting highly transferable adversarial examples and provides new insights into the dynamics of adversarial vulnerability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d12c3489-368d-433a-b52b-87a0ded44ad9Cited by top-tier papers2
- Boosting Adversarial Transferability via Ensemble Non-AttentionYipeng Zou, Qin Liu, Jie Wu, Yu Peng et al.AAAI 2026
- Consensus-Robust Transfer Attacks via Parameter and Representation PerturbationsShixin Li, Zewei Li, Xiaojing Ma, Xiaofan Bai et al.NeurIPS 2025
Builds on9
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Training data-efficient image transformers & distillation through attentionHugo Touvron, Matthieu Cord, Matthijs Douze, Francisco Massa et al.ICML 2021 · 8,974 citations
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Rethinking Spatial Dimensions of Vision TransformersByeongho Heo, Sangdoo Yun, Dongyoon Han, Sanghyuk Chun et al.ICCV 2021 · 733 citations
Related papers
- Boosting Black-Box Attack with Partially Transferred Conditional Adversarial DistributionYan Feng, Baoyuan Wu, Yanbo Fan, Li Liu et al.CVPR 2022 · 34 citations
- Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial TransferabilityYifeng Xiong, Jiadong Lin, Min Zhang, John E. Hopcroft et al.CVPR 2022 · 124 citations
- Blurred-Dilated Method for Adversarial AttacksYang Deng, Weibin Wu, Jianping Zhang, Zibin ZhengNeurIPS 2023 · 10 citations
- Training Meta-Surrogate Model for Transferable Adversarial AttackYunxiao Qin, Yuanhao Xiong, Jinfeng Yi, Cho-Jui HsiehAAAI 2023 · 31 citations
- A New Ensemble Adversarial Attack Powered by Long-Term Gradient MemoriesZhaohui Che, Ali Borji, Guangtao Zhai, Suiyi Ling et al.AAAI 2020 · 32 citations
