notesum.ai
Published at October 21Model Mimic Attack: Knowledge Distillation for Provably Transferable Adversarial Examples
cs.AI
Released Date: October 21, 2024
Authors: Kirill Lukyanov1, Andrew Perminov2, Denis Turdakov2, Mikhail Pautov3
Aff.: 1Research Center for Trusted Artificial Intelligence, Ivannikov Institute for System Programming of the Russian Academy of Sciences, Moscow Institute of Physics and Technology (National Research University), Moscow, Russia; 2Research Center for Trusted Artificial Intelligence, Ivannikov Institute for System Programming of the Russian Academy of Sciences, Moscow, Russia; 3AIRI, Research Center for Trusted Artificial Intelligence, Ivannikov Institute for System Programming of the Russian Academy of Sciences, Moscow, Russia

| Attack | AQN (ā) | ||
|---|---|---|---|
| CIFAR-10 | ZOO [Chen etĀ al. (2017)] | ||
| NES [Ilyas etĀ al. (2018)] | |||
| Square [Andriushchenko etĀ al. (2020)] | |||
| NP-Attack [Bai etĀ al. (2020)] (Lit) | |||
| MCG [Yin etĀ al. (2023)] (Lit) | |||
| MMAttack resnet18 (ours) | |||
| MMAttack SmallCNN (ours) | 32.8 | ||
| CIFAR-100 | ZOO [Chen etĀ al. (2017)] | ||
| NES [Ilyas etĀ al. (2018)] | |||
| Square [Andriushchenko etĀ al. (2020)] | |||
| NP-Attack [Bai etĀ al. (2020)] | |||
| MCG [Yin etĀ al. (2023)] (Lit) | |||
| MMAttack resnet18 (ours) | |||
| MMAttack SmallCNN (ours) | 24 |