{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T16:17:26Z","timestamp":1784823446814,"version":"3.55.0"},"reference-count":33,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2024,10,12]],"date-time":"2024-10-12T00:00:00Z","timestamp":1728691200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"funder":[{"name":"Zuckerman STEM Leadership","award":["952172"],"award-info":[{"award-number":["952172"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Intell. Syst. Technol."],"published-print":{"date-parts":[[2024,10,31]]},"abstract":"<jats:p>Adversarial transferability in blackbox scenarios presents a unique challenge: while attackers can employ surrogate models to craft adversarial examples, they lack assurance on whether these examples will successfully compromise the target model. Until now, the prevalent method to ascertain success has been trial and error\u2014testing crafted samples directly on the victim model. This approach, however, risks detection with every attempt, forcing attackers to either perfect their first try or face exposure.<\/jats:p>\n          <jats:p>Our article introduces a ranking strategy that refines the transfer attack process, enabling the attacker to estimate the likelihood of success without repeated trials on the victim\u2019s system. By leveraging a set of diverse surrogate models, our method can predict transferability of adversarial examples. This strategy can be used to either select the best sample to use in an attack or the best perturbation to apply to a specific sample.<\/jats:p>\n          <jats:p>Using our strategy, we were able to raise the transferability of adversarial examples from a mere 20%\u2014akin to random selection\u2014up to near upper-bound levels, with some scenarios even witnessing a 100% success rate. This substantial improvement not only sheds light on the shared susceptibilities across diverse architectures but also demonstrates that attackers can forego the detectable trial-and-error tactics raising increasing the threat of surrogate-based attacks.<\/jats:p>","DOI":"10.1145\/3670409","type":"journal-article","created":{"date-parts":[[2024,6,5]],"date-time":"2024-06-05T14:21:12Z","timestamp":1717597272000},"page":"1-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Ranking the Transferability of Adversarial Examples"],"prefix":"10.1145","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5061-4404","authenticated-orcid":false,"given":"Moshe","family":"Levy","sequence":"first","affiliation":[{"name":"Ben-Gurion University, Beersheba, Israel and Bar-Ilan University, Ramat Gan, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5987-4402","authenticated-orcid":false,"given":"Guy","family":"Amit","sequence":"additional","affiliation":[{"name":"Ben-Gurion University, Beersheba, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9641-128X","authenticated-orcid":false,"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[{"name":"Ben-Gurion University, Beersheba, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6367-2734","authenticated-orcid":false,"given":"Yisroel","family":"Mirsky","sequence":"additional","affiliation":[{"name":"Ben-Gurion University, Beersheba, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,10,12]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108245"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_4_2","first-page":"2206","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In Proceedings of the International Conference on Machine Learning. PMLR, ICML, 2206\u20132216."},{"key":"e_1_3_2_5_2","first-page":"321","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security\u201919)","author":"Demontis Ambra","year":"2019","unstructured":"Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019. Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks. In Proceedings of the 28th USENIX Security Symposium (USENIX Security\u201919). 321\u2013338."},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"e_1_3_2_9_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Goodfellow Ian","year":"2015","unstructured":"Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In Proceedings of the International Conference on Learning Representations. Retrieved from http:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","unstructured":"Ian J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572. Retrieved from 10.48550\/arXiv.1412.6572","DOI":"10.48550\/arXiv.1412.6572"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66399-9_4"},{"key":"e_1_3_2_12_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Guo Chuan","year":"2018","unstructured":"Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten. 2018. Countering adversarial images using input transformations. In Proceedings of the International Conference on Learning Representations. arXiv preprint arXiv:1711.00117"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1186\/s12880-020-00530-y"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1080\/02664763.2018.1441383"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","unstructured":"Ziv Katzir and Yuval Elovici. 2021. Who\u2019s afraid of adversarial transferability? arXiv:2105.00433. Retrieved from 10.48550\/arXiv.2105.00433","DOI":"10.48550\/arXiv.2105.00433"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","unstructured":"Moshe Levy Guy Amit Yuval Elovici and Yisroel Mirsky. 2022. The security of deep learning defences for medical imaging. arXiv:2201.08661. Retrieved from 10.48550\/arXiv.2201.08661","DOI":"10.48550\/arXiv.2201.08661"},{"key":"e_1_3_2_17_2","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083."},{"key":"e_1_3_2_18_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. In Proceedings of the International Conference on Learning Representations. arXiv preprint arXiv:1706.06083"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.02.056"},{"key":"e_1_3_2_20_2","doi-asserted-by":"crossref","unstructured":"Preetum Nakkiran. 2019. A discussion of \u2019adversarial examples are not bugs they are features\u2019: Adversarial examples are just bugs too. In Distill. Retrieved from https:\/\/distill.pub\/2019\/advex-bugs-discussion\/response-5","DOI":"10.23915\/distill.00019.5"},{"key":"e_1_3_2_21_2","first-page":"12905","article-title":"Cross-domain transferability of adversarial perturbations","volume":"32","author":"Naseer Muhammad Muzammal","year":"2019","unstructured":"Muhammad Muzammal Naseer, Salman H. Khan, Muhammad Haris Khan, Fahad Shahbaz Khan, and Fatih Porikli. 2019. Cross-domain transferability of adversarial perturbations. Advances in Neural Information Processing Systems 32, 12905\u201312915.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","unstructured":"Nicolas Papernot Patrick McDaniel and Ian Goodfellow. 2016. Transferability in machine learning: From phenomena to black-box attacks using adversarial samples. arXiv:1605.07277. Retrieved from 10.48550\/arXiv.1605.07277","DOI":"10.48550\/arXiv.1605.07277"},{"key":"e_1_3_2_23_2","series-title":"Purchase Printed Proceeding","first-page":"9759","volume-title":"Advances in Neural Information Processing Systems 34 (NeurIPS 2021)","author":"Springer Jacob M.","year":"2021","unstructured":"Jacob M. Springer, Melanie Mitchell, and Garrett T. Kenyon. 2021. A little robustness goes a long way: Leveraging robust features for targeted transfer attacks. In: M. Ranzato and A. Beygelzimer and Y. Dauphin and P.S. Liang and J. Wortman Vaughan (EDs.), Purchase Printed Proceeding Advances in Neural Information Processing Systems 34 (NeurIPS 2021). 9759\u20139773."},{"key":"e_1_3_2_24_2","volume-title":"Proceedings of the 2nd International Conference on Learning Representations (ICLR\u201914)","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In Proceedings of the 2nd International Conference on Learning Representations (ICLR\u201914). arXiv preprint arXiv:1312.6199"},{"key":"e_1_3_2_25_2","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"Tramer Florian","year":"2020","unstructured":"Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On adaptive attacks to adversarial example defenses. Advances in Neural Information Processing Systems 33, 1633\u20131645.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","unstructured":"Florian Tramr Nicolas Papernot Ian Goodfellow Dan Boneh and Patrick McDaniel. 2017. The space of transferable adversarial examples. arXiv:1704.03453. Retrieved from 10.48550\/arXiv.1704.03453","DOI":"10.48550\/arXiv.1704.03453"},{"key":"e_1_3_2_27_2","unstructured":"Renzhi Wang Tianwei Zhang Xiaofei Xie Lei Ma Cong Tian Felix Juefei-Xu and Yang Liu. 2020. Generating adversarial examples with controllable non-transferability. arXiv:2007.01299."},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"e_1_3_2_29_2","unstructured":"Ross Wightman Hugo Touvron and Herve Jegou. 2021. ResNet strikes back: An improved training procedure in timm. In NeurIPS 2021 Workshop on ImageNet: Past Present and Future. Retrieved from https:\/\/openreview.net\/forum?id=NG6MJnVl6M5"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00031"},{"key":"e_1_3_2_33_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Zhu Yao","year":"2021","unstructured":"Yao Zhu, Jiacheng Sun, and Zhenguo Li. 2021. Rethinking adversarial transferability from a data distribution perspective. In Proceedings of the International Conference on Learning Representations. Retrieved from https:\/\/openreview.net\/forum?id=NG6MJnVl6M5"},{"key":"e_1_3_2_34_2","volume-title":"Proceedings of the 32nd British Machine Vision Conference (BMVC) (Online). 15","author":"\u00d6zbulak Utku","year":"2021","unstructured":"Utku \u00d6zbulak, Esla Timothy Anzaku, Wesley De Neve, and Arnout Van Messem. 2021. Selection of source images heavily influences the effectiveness of adversarial attacks. In Proceedings of the 32nd British Machine Vision Conference (BMVC) (Online). 15. Retrieved from https:\/\/www.bmvc2021-virtualconference.com\/programme\/accepted-papers\/"}],"container-title":["ACM Transactions on Intelligent Systems and Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3670409","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3670409","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:05:38Z","timestamp":1750291538000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3670409"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,12]]},"references-count":33,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2024,10,31]]}},"alternative-id":["10.1145\/3670409"],"URL":"https:\/\/doi.org\/10.1145\/3670409","relation":{},"ISSN":["2157-6904","2157-6912"],"issn-type":[{"value":"2157-6904","type":"print"},{"value":"2157-6912","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,12]]},"assertion":[{"value":"2023-05-02","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-04-23","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-10-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}