CVNov 3, 2025

Beyond Deceptive Flatness: Dual-Order Solution for Strengthening Adversarial Transferability

arXiv:2511.01240v1h-index: 7Pattern Recognition
Originality Incremental advance
AI Analysis

This work addresses a critical bottleneck in adversarial machine learning for security applications, offering incremental improvements over existing methods.

The paper tackles the problem of deceptive flatness in transferable adversarial attacks by introducing a dual-order information approach, resulting in improved transferability across model architectures and outperforming six baselines on ImageNet-compatible datasets and real-world APIs.

Transferable attacks generate adversarial examples on surrogate models to fool unknown victim models, posing real-world threats and growing research interest. Despite focusing on flat losses for transferable adversarial examples, recent studies still fall into suboptimal regions, especially the flat-yet-sharp areas, termed as deceptive flatness. In this paper, we introduce a novel black-box gradient-based transferable attack from a perspective of dual-order information. Specifically, we feasibly propose Adversarial Flatness (AF) to the deceptive flatness problem and a theoretical assurance for adversarial transferability. Based on this, using an efficient approximation of our objective, we instantiate our attack as Adversarial Flatness Attack (AFA), addressing the altered gradient sign issue. Additionally, to further improve the attack ability, we devise MonteCarlo Adversarial Sampling (MCAS) by enhancing the inner-loop sampling efficiency. The comprehensive results on ImageNet-compatible dataset demonstrate superiority over six baselines, generating adversarial examples in flatter regions and boosting transferability across model architectures. When tested on input transformation attacks or the Baidu Cloud API, our method outperforms baselines.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes