[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126431-en":3,"doc-seo-126431-105":31,"detail-sidebar-cat-0-en-105":93},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},126431,962085564807,"Aurelia","https://ap-avatar.wpscdn.com/davatar_6f874abed73319feea01a86fa6f0fab8",8,"Research & Report","Game Theoretic Mixed Experts for Combinational Adversarial Machine Learning - 研究框架与攻击防御分析","Recent advances in adversarial machine learning show that defenses previously deemed robust can be undermined by customized adversarial attacks tuned to each defense’s weaknesses. This work investigates whether adversarial examples crafted for one defense strategy transfer effectively to other defenses, and how low transferability can be leveraged to increase robustness. It further studies adaptive white-box adversaries that jointly target multi-defense setups, and introduces game-theoretic frameworks combining multiple attacks and defenses, achieving improved robustness on CIFAR-10 and Tiny-ImageNet.","Received 14 August 2025, accepted 7 September 2025,  \ndate of publication 10 September 2025, date of current version 16 September 2025. Digital Object Identifier 10.1109/ACCESS.2025.3608117  \nGame Theoretic Mixed Experts for Combinational Adversarial Machine Learning  \nKALEEL MAHMOOD1, ETHAN RATHBUN2, RONAK SAHU3, MARTEN VAN DIJK4,(Fellow, IEEE), SOHAIB AHMAD5, AND CAIWEN DING6,(Member, IEEE)  \n1Department of Computer Science and Statistics, The University of Rhode Island, Kingston, RI 02881, USA  \n2Khoury College of Computer Sciences, Northeastern University, Boston, MA 02115, USA  \n3 School of Computing, University of Connecticut, Storrs, CT 06269, USA  \n4CWI Amsterdam, 1098 XG Amsterdam, The Netherlands  \n5Visa Inc., San Francisco, CA 94105, USA  \n6Department of Computer Science and Engineering, University of Minnesota, Minneapolis, MN 55455, USA Corresponding author: Kaleel Mahmood ([kaleel.mahmood@uri.edu](kaleel.mahmood@uri.edu))  \nABSTRACT Recent advances in adversarial machine learning have shown that defenses previously considered robust are actually susceptible to adversarial attacks which are specifically customized to target their weaknesses. However, whether the adversarial examples generated by customized attacks, are effective on other defenses, is an open question. In this work we seek to explore three important security questions: First, do different defense strategies exhibit the same low transferability properties as different model architectures and, if so, how can this low transferability be utilized to improve robustness? Second, how cana white-box adversary design attacks to specifically thwart multi-defense based setups? Last, how can game theoretic analysis further improve the robustness against an adversary capable of implementing multiple state-of-the-art attacks? To this end we provide multiple contributions, including the first transferability study between multiple defense strategies, three new attack algorithms designed to break random transform and ensemble defenses, and two game theoretic frameworks for analyzing and optimizing robustness over a combination of adversarial attacks and defenses. Empirically, we show our framework is 18% more robust on CIFAR-10 and is 27% more robust on Tiny-ImageNet than the best single state-of-the-art defense that we analzye.  \nINDEX TERMS Adversarial machine learning, adversarial examples, adversarial defense, deep learning.  \nI. INTRODUCTION  \nMachine learning models have been shown to be vulnerable to adversarial examples (AEs) [15],[33],[50] . AEs are inputs with small perturbations added, such that machine learning models misclassify them with high confidence. Addressing the security risks posed by AEs are critical for the safe deployment of machine learning in areas like health care [14] and self driving vehicles [35] . Current defenses and attacks in adversarial machine learning have trended towards a cat and mouse dynamic, where new defenses are being proposed and then broken [6], [26], [42], [44] by improved attacks. Many of these attacks are specialized to exploit particular vulnerabilities of specific defense strategies.  \nThe associate editor coordinating the review of this manuscript and  \napproving it for publication was SK Hafizul Islam  .  \nSome works [2], [29], [40] have looked at combinations of defenses as a solution to this dynamic. However, these works have shown limited improvements in robustness and fail to incorporate diverse set of defense and state-of-the-art strategies such as random transforms [36], [48] or diffusion based adversarial training [47] . They also do not consider the impact of adaptive attacks nor do they explore the optimization of their methods to defend against them.  \nIn parallel to attack and defense development, studies have also been conducted on the transferability of AEs [24],[27], [49] . Transferabiltiy refers to the phenomena where AEs generated for one model are also misclassified by a different machine learn","cbCaits8eORu1fO0","https://ap.wps.com/l/cbCaits8eORu1fO0","pdf",2403490,7,1,19,"English","en",105,"# Abstract\n# Introduction\n## Adversarial examples and security risks\n## Limitations of existing combined defenses\n## Transferability and open questions\n# Contributions\n## Defense transferability analysis\n## New adversarial attack algorithms\n## Game-theoretic frameworks","[{\"question\":\"本文研究的核心安全问题是什么？\",\"answer\":\"研究重点包括：不同防御策略是否存在相同的低迁移性、如何利用这种低迁移性提升鲁棒性、白盒对手如何联合攻击多防御设置，以及如何用博弈论进一步增强面对多种最先进攻击的防御能力。\"},{\"question\":\"本文如何分析对抗样本在不同防御策略之间的迁移性？\",\"answer\":\"作者对多种前沿防御策略进行跨防御迁移评估，展示针对特定防御的攻击不易迁移到其他防御，从而暗示可在博弈论框架下构建组合防御。\"},{\"question\":\"本文提出了哪些用于提升鲁棒性的关键方法？\",\"answer\":\"作者提供了三类新的对抗攻击算法来破坏随机变换与集成类防御，并提出两种博弈论框架，用于分析与优化多种攻击与防御组合，从而在CIFAR-10与Tiny-ImageNet上优于单一最佳防御。\"}]","Game Theoretic Mixed Experts for Combinational Adversarial Machine Learning - 研究框架与攻击防御分析 | PDF",1785905032,48,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":88,"head_meta":90,"extra_data":92,"updated_unix":29},"game-theoretic-mixed-experts-for-combinational-adversarial-machine-learning-research-frameworks-and-attack-defense-analysis","",{"@graph":37,"@context":87},[38,55,70],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":54},"https://docshare.wps.com/document/game-theoretic-mixed-experts-for-combinational-adversarial-machine-learning-research-frameworks-and-attack-defense-analysis/126431/",4,{"url":53,"name":13,"@type":56,"author":57,"headline":13,"publisher":59,"fileFormat":62,"inLanguage":24,"description":14,"dateModified":63,"datePublished":64,"encodingFormat":62,"isAccessibleForFree":65,"interactionStatistic":66},"DigitalDocument",{"name":9,"@type":58},"Person",{"url":42,"name":60,"@type":61},"DocShare","Organization","application/pdf","2026-08-25","2026-08-05",true,{"@type":67,"interactionType":68,"userInteractionCount":20},"InteractionCounter",{"@type":69},"ViewAction",{"@type":71,"mainEntity":72},"FAQPage",[73,79,83],{"name":74,"@type":75,"acceptedAnswer":76},"本文研究的核心安全问题是什么？","Question",{"text":77,"@type":78},"研究重点包括：不同防御策略是否存在相同的低迁移性、如何利用这种低迁移性提升鲁棒性、白盒对手如何联合攻击多防御设置，以及如何用博弈论进一步增强面对多种最先进攻击的防御能力。","Answer",{"name":80,"@type":75,"acceptedAnswer":81},"本文如何分析对抗样本在不同防御策略之间的迁移性？",{"text":82,"@type":78},"作者对多种前沿防御策略进行跨防御迁移评估，展示针对特定防御的攻击不易迁移到其他防御，从而暗示可在博弈论框架下构建组合防御。",{"name":84,"@type":75,"acceptedAnswer":85},"本文提出了哪些用于提升鲁棒性的关键方法？",{"text":86,"@type":78},"作者提供了三类新的对抗攻击算法来破坏随机变换与集成类防御，并提出两种博弈论框架，用于分析与优化多种攻击与防御组合，从而在CIFAR-10与Tiny-ImageNet上优于单一最佳防御。","https://schema.org",{"og:url":53,"og:type":89,"og:title":13,"og:site_name":60,"og:description":14},"article",{"robots":91,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":94},[95,99,103,107,112,117,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":96,"show_sort_weight":97,"slug":98},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":100,"show_sort_weight":101,"slug":102},"Literature",80,"literature",{"id":54,"doc_module":4,"doc_module_name":47,"category_name":104,"show_sort_weight":105,"slug":106},"Exam",70,"exam",{"id":108,"doc_module":4,"doc_module_name":47,"category_name":109,"show_sort_weight":110,"slug":111},5,"Comic",60,"comic",{"id":113,"doc_module":4,"doc_module_name":47,"category_name":114,"show_sort_weight":115,"slug":116},6,"Technology",50,"technology",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":22,"doc_module":4,"doc_module_name":47,"category_name":137,"show_sort_weight":108,"slug":138},"General","general"]