The Scissors Effect: When Resize-Based Input Diversity Helps or Hurts Transfer Attacks
cs.LG, cs.CR, cs.CV
Submitted: 2026-06-21
Updated: 2026-09-15
Comments: Camera-ready version, published in Transactions on Machine Learning Research (2026). Project page: https://avalon-s.github.io/ScissorsEffect/
Journal ref: Transactions on Machine Learning Research, 2026
Code: https://github.com/Avalon-S/ScissorsEffect
Project page: https://avalon-s.github.io/ScissorsEffect
License: http://creativecommons.org/licenses/by/4.0/
The gist: Input Diversity (DI), a random resize and pad applied at each attack iteration, is a near-default ingredient of transfer-based attacks, widely assumed to improve transferability.
Terminology
Abstract
Input Diversity (DI), a random resize and pad applied at each attack iteration, is a near-default ingredient of transfer-based attacks, widely assumed to improve transferability. We show this assumption is regime-dependent and, for adversarially trained surrogates, often reversed. Holding the attack fixed and varying only the surrogate, raising the DI probability improves transfer from standard surrogates but degrades it from robust ones: the two response curves separate like a pair of scissors, a pattern we call the Scissors Effect. On ImageNet, blind DI costs a robust source 10.3 percentage points of attack success across four architecturally diverse targets; the effect is several times smaller at 32x32. Direct measurement supports a bias-variance account: DI displaces the gradient by a comparable amount on both groups but reduces its variance only where the gradient is noisy, and robust surrogates have little noise left to average away. A gradient-consistency probe, frozen and hashed before the runs, predicts the sign of the effect on seven unseen surrogates, and we report where it fails alongside where it works. The practical consequence holds independently of the mechanism: leaving DI enabled by default understates the attack a robust surrogate can mount, and so overstates the robustness of the model being evaluated. Code: https://github.com/Avalon-S/ScissorsEffect.
Sources
- Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples
- Torchattacks: A PyTorch Repository for Adversarial Attacks
- Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples
Related papers
- Polynomial-Augmented Neural Networks (PANNs) with Weak Orthogonality Constraints for Enhanced Function and PDE Approximation
- AIRL-S: Unifying Reinforcement Learning and Search-Based Test-Time Scaling via Adversarial Inverse Reinforcement Learning
- Transformers as Bayesian In-Context Experimenters: Smoothness-Adaptive Efficient ATE Estimation
- Convergence issues in Relational Concept Analysis based on AOC-posets
- Beliefs Beyond Posteriors: Local-Consistency Optimisation for Bayesian Neural Networks
- Understanding Diffusion Models via Ratio-Based Function Approximation with SignReLU Networks