{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/caad-2018-generating-transferable-adversarial","title":"CAAD 2018: Generating Transferable Adversarial Examples","arxiv_id":"1810.01268","date":"2018-09-29","proceeding":null,"authors":["Yash Sharma","Tien-Dung Le","Moustafa Alzantot"],"abstract":"Deep neural networks (DNNs) are vulnerable to adversarial examples,\nperturbations carefully crafted to fool the targeted DNN, in both the\nnon-targeted and targeted case. In the non-targeted case, the attacker simply\naims to induce misclassification. In the targeted case, the attacker aims to\ninduce classification to a specified target class. In addition, it has been\nobserved that strong adversarial examples can transfer to unknown models,\nyielding a serious security concern. The NIPS 2017 competition was organized to\naccelerate research in adversarial attacks and defenses, taking place in the\nrealistic setting where submitted adversarial attacks attempt to transfer to\nsubmitted defenses. The CAAD 2018 competition took place with nearly identical\nrules to the NIPS 2017 one. Given the requirement that the NIPS 2017\nsubmissions were to be open-sourced, participants in the CAAD 2018 competition\nwere able to directly build upon previous solutions, and thus improve the\nstate-of-the-art in this setting. Our team participated in the CAAD 2018\ncompetition, and won 1st place in both attack subtracks, non-targeted and\ntargeted adversarial attacks, and 3rd place in defense. We outline our\nsolutions and development results in this article. We hope our results can\ninform researchers in both generating and defending against adversarial\nexamples.","url_abs":"http://arxiv.org/abs/1810.01268v2","url_pdf":"http://arxiv.org/pdf/1810.01268v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"caad-2018-generating-transferable-adversarial","repo_url":"https://github.com/ysharma1126/caad_18","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"adversarial-defense","task_name":"Adversarial Defense"},{"task_slug":"adversarial-robustness","task_name":"Adversarial Robustness"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}