arXiv (Cornell University)
Boosting Adversarial Transferability via Ensemble Non-Attention
November 2025 • Yuan Zou, Qin Liu, Jie Wu, Guanrong Chen
Ensemble attacks integrate the outputs of surrogate models with diverse architectures, which can be combined with various gradient-based attacks to improve adversarial transferability. However, previous work shows unsatisfactory attack performance when transferring across heterogeneous model architectures. The main reason is that the gradient update directions of heterogeneous surrogate models differ widely, making it hard to reduce the gradient variance of ensemble models while making the best of individual model…