{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/boosting-adversarial-attacks-with-momentum","title":"Boosting Adversarial Attacks with Momentum","arxiv_id":"1710.06081","date":"2017-10-17","proceeding":"CVPR 2018 6","authors":["Yinpeng Dong","Fangzhou Liao","Tianyu Pang","Hang Su","Jun Zhu","Xiaolin Hu","Jianguo Li"],"abstract":"Deep neural networks are vulnerable to adversarial examples, which poses\nsecurity concerns on these algorithms due to the potentially severe\nconsequences. Adversarial attacks serve as an important surrogate to evaluate\nthe robustness of deep learning models before they are deployed. However, most\nof existing adversarial attacks can only fool a black-box model with a low\nsuccess rate. To address this issue, we propose a broad class of momentum-based\niterative algorithms to boost adversarial attacks. By integrating the momentum\nterm into the iterative process for attacks, our methods can stabilize update\ndirections and escape from poor local maxima during the iterations, resulting\nin more transferable adversarial examples. To further improve the success rates\nfor black-box attacks, we apply momentum iterative algorithms to an ensemble of\nmodels, and show that the adversarially trained models with a strong defense\nability are also vulnerable to our black-box attacks. We hope that the proposed\nmethods will serve as a benchmark for evaluating the robustness of various deep\nmodels and defense methods. With this method, we won the first places in NIPS\n2017 Non-targeted Adversarial Attack and Targeted Adversarial Attack\ncompetitions.","url_abs":"http://arxiv.org/abs/1710.06081v3","url_pdf":"http://arxiv.org/pdf/1710.06081v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"boosting-adversarial-attacks-with-momentum","repo_url":"https://github.com/dongyp13/Non-Targeted-Adversarial-Attacks","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok","spdx":"Apache-2.0"}},{"paper_slug":"boosting-adversarial-attacks-with-momentum","repo_url":"https://github.com/dongyp13/Targeted-Adversarial-Attack","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok","spdx":"Apache-2.0"}},{"paper_slug":"boosting-adversarial-attacks-with-momentum","repo_url":"https://github.com/Trustworthy-AI-Group/TransferAttack","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null},{"paper_slug":"boosting-adversarial-attacks-with-momentum","repo_url":"https://github.com/albertmillan/adversarial-training-pytorch","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null},{"paper_slug":"boosting-adversarial-attacks-with-momentum","repo_url":"https://github.com/as791/Adversarial-Example-Attack-and-Defense","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"torch","reach":{"status":"ok"}},{"paper_slug":"boosting-adversarial-attacks-with-momentum","repo_url":"https://github.com/henry8527/GCE","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"boosting-adversarial-attacks-with-momentum","repo_url":"https://github.com/srk97/targeted-adversarial-mnist","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok"}}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1710.06081","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1710.06081"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/Trustworthy-AI-Group/TransferAttack","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/srk97/targeted-adversarial-mnist","reach":{"status":"ok"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/dongyp13/Non-Targeted-Adversarial-Attacks","reach":{"status":"ok","spdx":"Apache-2.0"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/dongyp13/Targeted-Adversarial-Attack","reach":{"status":"ok","spdx":"Apache-2.0"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/albertmillan/adversarial-training-pytorch","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/as791/Adversarial-Example-Attack-and-Defense","reach":{"status":"ok"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/henry8527/GCE","reach":{"status":"ok"}}],"summary":{"ran":1,"unverified":1},"by_repo_kind":{"official":{"samples":2,"ran":1,"repositories":2}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"b6e06004f7efe660","entry":"wrapped_partial","repo":"dongyp13/Non-Targeted-Adversarial-Attacks","repo_kind":"official","path":"nets/mobilenet_v1.py","file_url":"https://github.com/dongyp13/Non-Targeted-Adversarial-Attacks/blob/HEAD/nets/mobilenet_v1.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"b6e06004f7efe660"}},{"code_sha256_prefix":"3ce9b0c9fd46f784","entry":"load_target_class","repo":"dongyp13/Targeted-Adversarial-Attack","repo_kind":"official","path":"target_attack.py","file_url":"https://github.com/dongyp13/Targeted-Adversarial-Attack/blob/HEAD/target_attack.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"3ce9b0c9fd46f784"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}