[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119492-en":3,"doc-seo-119492-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119492,962075114101,"Seraphina","https://ap-avatar.wpscdn.com/avatar/e000253a75eb197efd?x-image-process=image/resize,m_fixed,w_180,h_180&k=1780044092746381165",8,"Research & Report","A Survey on Transferability of Adversarial Examples Across Deep Neural Networks - survey overview","Deep Neural Networks enable breakthroughs in image recognition, natural language processing, and scientific problem-solving, but they also expose a critical weakness: adversarial examples. These crafted, human-imperceptible inputs can force models to produce incorrect predictions, endangering safety-critical applications such as medical image analysis and autonomous driving. A key property is transferability, where perturbations optimized for one architecture can mislead different models, enabling black-box attacks without target-model details. This survey maps transferability-enhancing methods, summarizes principles, and discusses challenges and opportunities beyond image classification.","A Survey on Transferability of Adversarial Examples Across Deep Neural Networks  \nJindong Gu 1 , Xiaojun Jia2 , Pau de Jorge 1 , Wenqain Yu3 , Xinwei Liu4 , Avery Ma5 , Yuan Xun4 , Anjun Hu 1 , Ashkan Khakzar 1 , Zhijiang Li3 , Xiaochun Cao6 , Philip Torr 1  \n1 Torr Vision Group, University of Oxford, Oxford, United Kingdom  \n2 Nanyang Technological University, Singapore  \n3 Wuhan University, Wuhan, China  \n4 University of Chinese Academy of Sciences, Beijing, China  \n5 University of Toronto, Toronto, Canada  \n6 Sun Yat-sen University, Shenzhen, China  \nReviewed on OpenReview: [https: // openreview. net/ forum? id= AYJ3m7BocI](https: // openreview. net/ forum? id= AYJ3m7BocI)  \nAbstract  \nThe emergence of Deep Neural Networks (DNNs) has revolutionized various domains by enabling the resolution of complex tasks spanning image recognition, natural language processing, and scientific problem-solving. However, this progress has also brought to light a concerning vulnerability: adversarial examples. These crafted inputs, imperceptible to humans, can manipulate machine learning models into making erroneous predictions, raising concerns for safety-critical applications. An intriguing property of this phenomenon is the transferability of adversarial examples, where perturbations crafted for one model can deceive another, often with a different architecture. This intriguing property enables“black-box” attacks which circumvents the need for detailed knowledge of the target model.  \nThis survey explores the landscape of the adversarial transferability of adversarial examples.  \nWe categorize existing methodologies to enhance adversarial transferability and discuss the fundamental principles guiding each approach. While the predominant body of research primarily concentrates on image classification, we also extend our discussion to encompass other vision tasks and beyond. Challenges and opportunities are discussed, highlighting the importance of fortifying DNNs against adversarial vulnerabilities in an evolving landscape.  \n1 Introduction  \nIn recent years, Deep Neural Network (DNN) has evolved as a powerful tool for solving complex tasks, ranging from image recognition (He et al., 2016; Dosovitskiy et al., 2020) and natural language processing (Kenton & Toutanova, 2019; Brown et al., 2020a) to natural science problems (Wang et al., 2023) . Since the advent of neural networks, an intriguing and disconcerting phenomenon known as adversarial examples has come into focus (Szegedy et al., 2013; Goodfellow et al., 2014) . Adversarial examples are specially crafted inputs that lead machine learning models to make incorrect predictions. These inputs are imperceptibly different from correctly predicted inputs. The existence of adversarial examples poses potential threats to real-world safety-critical DNN-based applications, e.g., medical image analysis (Bortsova et al., 2021) and autonomous driving systems (Kim & Canny, 2017; Kim et al., 2018) .  \nWhile the existence of adversarial examples has raised concerns about the robustness and reliability of machine learning systems, researchers have uncovered an even more intriguing phenomenon: the transferability of adversarial examples (Goodfellow et al., 2014; Papernot et al., 2016) . Transferability refers to the ability of an adversarial example designed for one model to successfully deceive a different model, often one with a distinct architecture. With such a property, a successful attack can be implemented without accessing any detail of the target model, such as model architecture, model parameters, and training data.  \nTable 1: Categorization of transferability-enhancing methods.  \n\n| Optimization\u003Cbr>Based |  | Data Augmentation | Xie et al. (2019); Dong et al. (2019); Lin et al. (2019); Zou et al. (2020); Wu et al. (2021); Li et al. (2020b); Byun et al. (2022); Wang et al.(2021a); Huang & Kong (2022) |\n| --- | --- | --- | --- |\n|  |  | Optimization Technique | Goodfellow et al. (2014); Dong et","cbCaihTpldw474TB","https://ap.wps.com/l/cbCaihTpldw474TB","pdf",610998,1,35,"English","en",105,"# Introduction\n## Adversarial examples and DNN vulnerabilities\n## Transferability and black-box attacks\n## Categorization of transferability-enhancing methods","[{\"question\":\"What are adversarial examples and why are they concerning for deep neural networks?\",\"answer\":\"Adversarial examples are specially crafted inputs that differ imperceptibly from normal inputs but cause DNNs to make incorrect predictions. This threatens safety-critical uses such as medical imaging and autonomous driving.\"},{\"question\":\"What does transferability mean in the context of adversarial attacks?\",\"answer\":\"Transferability means an adversarial example designed for one model can successfully deceive another model, often with a different architecture. This enables attacks without needing access to the target model’s architecture, parameters, or training data.\"},{\"question\":\"How does the survey organize methods that improve adversarial transferability?\",\"answer\":\"The survey categorizes transferability-enhancing methodologies and explains the fundamental principles behind each approach. It also extends discussion beyond image classification to other vision tasks and related areas.\"}]","A Survey on Transferability of Adversarial Examples Across Deep Neural Networks - survey overview | PDF",1785724603,88,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"a-survey-on-transferability-of-adversarial-examples-across-deep-neural-networks-survey-overview","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/a-survey-on-transferability-of-adversarial-examples-across-deep-neural-networks-survey-overview/119492/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What are adversarial examples and why are they concerning for deep neural networks?","Question",{"text":75,"@type":76},"Adversarial examples are specially crafted inputs that differ imperceptibly from normal inputs but cause DNNs to make incorrect predictions. This threatens safety-critical uses such as medical imaging and autonomous driving.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What does transferability mean in the context of adversarial attacks?",{"text":80,"@type":76},"Transferability means an adversarial example designed for one model can successfully deceive another model, often with a different architecture. This enables attacks without needing access to the target model’s architecture, parameters, or training data.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the survey organize methods that improve adversarial transferability?",{"text":84,"@type":76},"The survey categorizes transferability-enhancing methodologies and explains the fundamental principles behind each approach. It also extends discussion beyond image classification to other vision tasks and related areas.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]