Machine Learning (ML) models are known to be vulnerable to adversarial inputs\nand researchers have demonstrated that even production systems, such as\nself-driving cars and ML-as-a-service offerings, are susceptible. These systems\nrepresent a target for bad actors. Their disruption can cause real physical and\neconomic harm. When attacks on production ML systems occur, the ability to\nattribute the attack to the responsible threat group is a critical step in\nformulating a response and holding the attackers accountable. We pose the\nfollowing question: can adversarially perturbed inputs be attributed to the\nparticular methods used to generate the attack? In other words, is there a way\nto find a signal in these attacks that exposes the attack algorithm, model\narchitecture, or hyperparameters used in the attack? We introduce the concept\nof adversarial attack attribution and create a simple supervised learning\nexperimental framework to examine the feasibility of discovering attributable\nsignals in adversarial attacks. We find that it is possible to differentiate\nattacks generated with different attack algorithms, models, and hyperparameters\non both the CIFAR-10 and MNIST datasets.\n