Pith. sign in

REVIEW 2 cited by

Query-Free Adversarial Transfer via Undertrained Surrogates

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2007.00806 v2 pith:GEQDHEBX submitted 2020-07-01 cs.CV cs.LG

classification cs.CVcs.LG
keywords modeladversarialmethodattackssurrogateapproacharchitecturesfunction
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Deep neural networks are vulnerable to adversarial examples -- minor perturbations added to a model's input which cause the model to output an incorrect prediction. We introduce a new method for improving the efficacy of adversarial attacks in a black-box setting by undertraining the surrogate model which the attacks are generated on. Using two datasets and five model architectures, we show that this method transfers well across architectures and outperforms state-of-the-art methods by a wide margin. We interpret the effectiveness of our approach as a function of reduced surrogate model loss function curvature and increased universal gradient characteristics, and show that our approach reduces the presence of local loss maxima which hinder transferability. Our results suggest that finding strong single surrogate models is a highly effective and simple method for generating transferable adversarial attacks, and that this method represents a valuable route for future study in this field.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Learning with Bilevel-Minimax Optimization for Efficient and Reliable Transfer Attacks

    cs.LG 2026-08 conditional novelty 6.0 of 10

    BMAT couples initialization, perturbation, and surrogate adaptation in one bilevel-minimax optimization, markedly improving adversarial example transfer to unseen victims.

  2. Social Popularity of GitHub Projects: A Lifeline or a Liability?

    cs.SE 2026-07 unverdicted novelty 6.0 of 10

    Survival analysis of 73k GitHub repositories finds human capital critical for survival while social popularity plus accessibility features raises inactivity risk, with contributor count moderating the effect.

Pith tools