{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/the-space-of-transferable-adversarial","title":"The Space of Transferable Adversarial Examples","arxiv_id":"1704.03453","date":"2017-04-11","proceeding":null,"authors":["Florian Tramèr","Nicolas Papernot","Ian Goodfellow","Dan Boneh","Patrick McDaniel"],"abstract":"Adversarial examples are maliciously perturbed inputs designed to mislead\nmachine learning (ML) models at test-time. They often transfer: the same\nadversarial example fools more than one model.\n  In this work, we propose novel methods for estimating the previously unknown\ndimensionality of the space of adversarial inputs. We find that adversarial\nexamples span a contiguous subspace of large (~25) dimensionality. Adversarial\nsubspaces with higher dimensionality are more likely to intersect. We find that\nfor two different models, a significant fraction of their subspaces is shared,\nthus enabling transferability.\n  In the first quantitative analysis of the similarity of different models'\ndecision boundaries, we show that these boundaries are actually close in\narbitrary directions, whether adversarial or benign. We conclude by formally\nstudying the limits of transferability. We derive (1) sufficient conditions on\nthe data distribution that imply transferability for simple model classes and\n(2) examples of scenarios in which transfer does not occur. These findings\nindicate that it may be possible to design defenses against transfer-based\nattacks, even for models that are vulnerable to direct attacks.","url_abs":"http://arxiv.org/abs/1704.03453v2","url_pdf":"http://arxiv.org/pdf/1704.03453v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"the-space-of-transferable-adversarial","repo_url":"https://github.com/panda1230/Adversarial_NoiseLearning_NoL","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"unanswered"}},{"paper_slug":"the-space-of-transferable-adversarial","repo_url":"https://github.com/tj-kim/pfeddef_v1","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1704.03453","atlas_url":"https://app.syntology.ai/?focus=1704.03453","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}