The paper introduces Manifold Anchored Bilevel Transfer (MABT), a framework that aligns adversarial attack trajectories with the intrinsic data manifold to reduce surrogate-specific overfitting. MABT employs a relaxed manifold-anchoring operator as a semantic rectifier and formulates transfer attack generation as a distributional bilevel optimization problem, learning geometry-aligned initializations that minimize expected transfer risk. A Hessian-free solver with linear-time complexity is developed to efficiently solve the resulting hierarchy, and experiments show improved transferability across 10 attackers, 28 configurations, various victim models, and defense mechanisms.
By Yaohua Liu, Yifan Guo, Jiaxin Gao
The paper introduces Inverse Knowledge Distillation (IKD), an attack‑agnostic technique that enhances adversarial transferability by maximizing the discrepancy between benign and adversarial prediction distributions on a surrogate model. IKD employs a CE/KL‑equivalent soft‑label objective to push adversarial predictions away from a fixed benign anchor, leveraging Fisher‑sensitive surrogate directions. The authors provide theoretical analysis showing CE and KL induce identical gradients, derive a lower bound on Fisher‑subspace overlap, and demonstrate through extensive ImageNet experiments that IKD consistently improves black‑box attack performance across CNN, ViT, and defended models.
By Wenyuan Wu, Yuan Sun, Yingke Chen, Chao Su, Xi Peng, Dezhong Peng, Xu Wang
arXiv:2509. 23689v2 Announce Type: replace Abstract: Model Merging (MM) has proven to be an effective alternative to multi-task learning, where several fine-tuned models are merged, without access to the tasks' training data, into one model that retains performance across different tasks.
By Mauro Conti, Ankit Gangwal, Aaryan Ajay Sharma
arXiv:2602.08136v2 Announce Type: replace-cross
Abstract: Vision-Language Models (VLMs) are now a core part of modern AI. Recent work proposed several visual jailbreak attacks using single/ holistic...
By Md Rafi Ur Rashid, MD Sadik Hossain Shanto, Vishnu Asutosh Dasu, Shagufta Mehnaz
arXiv:2607. 28959v1 Announce Type: cross Abstract: Adversarial training is one of the most effective defenses against adversarial attacks, yet the computational cost remains prohibitive at modern scales, especially for large language models (LLMs).
By Weiyi He, Yuping Lin, Jiliang Tang, Yue Xing
arXiv:2607. 04145v1 Announce Type: new Abstract: Adversarial attacks guide and provide additional training and test data for both adversarial training and adversarial robustness validation, and expose the 'piecewise linearity' of deep learning based models.
By Naman Goyal, Milan Chaudhari