{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/improving-adversarial-transferability-via-3","title":"Improving Adversarial Transferability via Intermediate-level Perturbation Decay","arxiv_id":"2304.13410","date":"2023-04-26","proceeding":"NeurIPS 2023 11","authors":["Qizhang Li","Yiwen Guo","WangMeng Zuo","Hao Chen"],"abstract":"Intermediate-level attacks that attempt to perturb feature representations following an adversarial direction drastically have shown favorable performance in crafting transferable adversarial examples. Existing methods in this category are normally formulated with two separate stages, where a directional guide is required to be determined at first and the scalar projection of the intermediate-level perturbation onto the directional guide is enlarged thereafter. The obtained perturbation deviates from the guide inevitably in the feature space, and it is revealed in this paper that such a deviation may lead to sub-optimal attack. To address this issue, we develop a novel intermediate-level method that crafts adversarial examples within a single stage of optimization. In particular, the proposed method, named intermediate-level perturbation decay (ILPD), encourages the intermediate-level perturbation to be in an effective adversarial direction and to possess a great magnitude simultaneously. In-depth discussion verifies the effectiveness of our method. Experimental results show that it outperforms state-of-the-arts by large margins in attacking various victim models on ImageNet (+10.07% on average) and CIFAR-10 (+3.88% on average). Our code is at https://github.com/qizhangli/ILPD-attack.","url_abs":"https://arxiv.org/abs/2304.13410v3","url_pdf":"https://arxiv.org/pdf/2304.13410v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"improving-adversarial-transferability-via-3","repo_url":"https://github.com/qizhangli/ilpd-attack","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"improving-adversarial-transferability-via-3","repo_url":"https://github.com/Trustworthy-AI-Group/TransferAttack","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2304.13410","atlas_url":"https://app.syntology.ai/?focus=2304.13410","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2304.13410"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/qizhangli/ILPD-attack","reach":{"status":"ok"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/Trustworthy-AI-Group/TransferAttack","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/qizhangli/ilpd-attack","reach":{"status":"ok"}}],"summary":{"ran_draft_wrong":2,"unverified":4},"by_repo_kind":{"official":{"samples":3,"ran":1,"repositories":1},"listed":{"samples":3,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"464ccf466c650f82","entry":"get_hook_pd","repo":"Trustworthy-AI-Group/TransferAttack","repo_kind":"listed","path":"transferattack/advanced_objective/ilpd.py","file_url":"https://github.com/Trustworthy-AI-Group/TransferAttack/blob/HEAD/transferattack/advanced_objective/ilpd.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"464ccf466c650f82"}},{"code_sha256_prefix":"5664336771c7620d","entry":"to_np_uint8","repo":"qizhangli/ilpd-attack","repo_kind":"official","path":"attacks/ilpd.py","file_url":"https://github.com/qizhangli/ilpd-attack/blob/HEAD/attacks/ilpd.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"5664336771c7620d"}},{"code_sha256_prefix":"6c9081765f65818c","entry":"ILPD","repo":"Trustworthy-AI-Group/TransferAttack","repo_kind":"listed","path":"transferattack/advanced_objective/ilpd.py","file_url":"https://github.com/Trustworthy-AI-Group/TransferAttack/blob/HEAD/transferattack/advanced_objective/ilpd.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"6c9081765f65818c"}},{"code_sha256_prefix":"8c1532a7891f491e","entry":"ILPD","repo":"qizhangli/ilpd-attack","repo_kind":"official","path":"attacks/ilpd.py","file_url":"https://github.com/qizhangli/ilpd-attack/blob/HEAD/attacks/ilpd.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"8c1532a7891f491e"}},{"code_sha256_prefix":"c6f475139b3e8ae2","entry":"get_hook_pd","repo":"qizhangli/ilpd-attack","repo_kind":"official","path":"attacks/ilpd.py","file_url":"https://github.com/qizhangli/ilpd-attack/blob/HEAD/attacks/ilpd.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"c6f475139b3e8ae2"}},{"code_sha256_prefix":"2314d29d07871ba1","entry":"hook_ilout","repo":"Trustworthy-AI-Group/TransferAttack","repo_kind":"listed","path":"transferattack/advanced_objective/ilpd.py","file_url":"https://github.com/Trustworthy-AI-Group/TransferAttack/blob/HEAD/transferattack/advanced_objective/ilpd.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"2314d29d07871ba1"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}