{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/making-substitute-models-more-bayesian-can","title":"Making Substitute Models More Bayesian Can Enhance Transferability of Adversarial Examples","arxiv_id":"2302.05086","date":"2023-02-10","proceeding":null,"authors":["Qizhang Li","Yiwen Guo","WangMeng Zuo","Hao Chen"],"abstract":"The transferability of adversarial examples across deep neural networks (DNNs) is the crux of many black-box attacks. Many prior efforts have been devoted to improving the transferability via increasing the diversity in inputs of some substitute models. In this paper, by contrast, we opt for the diversity in substitute models and advocate to attack a Bayesian model for achieving desirable transferability. Deriving from the Bayesian formulation, we develop a principled strategy for possible finetuning, which can be combined with many off-the-shelf Gaussian posterior approximations over DNN parameters. Extensive experiments have been conducted to verify the effectiveness of our method, on common benchmark datasets, and the results demonstrate that our method outperforms recent state-of-the-arts by large margins (roughly 19% absolute increase in average attack success rate on ImageNet), and, by combining with these recent methods, further performance gain can be obtained. Our code: https://github.com/qizhangli/MoreBayesian-attack.","url_abs":"https://arxiv.org/abs/2302.05086v3","url_pdf":"https://arxiv.org/pdf/2302.05086v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"making-substitute-models-more-bayesian-can","repo_url":"https://github.com/qizhangli/morebayesian-attack","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[{"task_slug":"diversity","task_name":"Diversity"}],"methods":[{"method_slug":"opt","method_name":"OPT"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2302.05086","atlas_url":"https://app.syntology.ai/?focus=2302.05086","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2302.05086"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/qizhangli/MoreBayesian-attack","reach":{"status":"ok"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/qizhangli/morebayesian-attack","reach":{"status":"ok"}}],"summary":{"ran_draft_wrong":2,"ran_fixture":1},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"d90cc0441c7416c8","entry":"get_input_grad","repo":"qizhangli/morebayesian-attack","repo_kind":"official","path":"attacks/morebayesian.py","file_url":"https://github.com/qizhangli/morebayesian-attack/blob/HEAD/attacks/morebayesian.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"d90cc0441c7416c8"}},{"code_sha256_prefix":"9f956dcf50723275","entry":"morebayesian_attack","repo":"qizhangli/morebayesian-attack","repo_kind":"official","path":"attacks/morebayesian.py","file_url":"https://github.com/qizhangli/morebayesian-attack/blob/HEAD/attacks/morebayesian.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"9f956dcf50723275"}},{"code_sha256_prefix":"7d0a309b1c2a996b","entry":"update_and_clip","repo":"qizhangli/morebayesian-attack","repo_kind":"official","path":"attacks/morebayesian.py","file_url":"https://github.com/qizhangli/morebayesian-attack/blob/HEAD/attacks/morebayesian.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"7d0a309b1c2a996b"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}