Backpropagating Linearly Improves Transferability of Adversarial Examples

The vulnerability of deep neural networks (DNNs) to adversarial examples has\ndrawn great attention from the community. In this paper, we study the\ntransferability of such examples, which lays the foundation of many black-box\nattacks on DNNs. We revisit a not so new but definitely noteworthy hypothesis\nof Goodfellow et al.'s and disclose that the transferability can be enhanced by\nimproving the linearity of DNNs in an appropriate manner. We introduce linear\nbackpropagation (LinBP), a method that performs backpropagation in a more\nlinear fashion using off-the-shelf attacks that exploit gradients. More\nspecifically, it calculates forward as normal but backpropagates loss as if\nsome nonlinear activations are not encountered in the forward pass.\nExperimental results demonstrate that this simple yet effective method\nobviously outperforms current state-of-the-arts in crafting transferable\nadversarial examples on CIFAR-10 and ImageNet, leading to more effective\nattacks on a variety of DNNs.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC