[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-a-reversed-ai-training-trick-boosts-adversarial-attack-transfer":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},6942,"a-reversed-ai-training-trick-boosts-adversarial-attack-transfer","A Reversed AI Training Trick Boosts Adversarial Attack Transfer","A flipped knowledge-distillation trick pushes adversarial images away from a model's own predictions, helping attacks transfer across architectures.","A new adversarial-attack technique borrows from AI training itself, but runs it backward.\n\nA research team describes Inverse Knowledge Distillation (IKD), a plug-in for existing transfer-based adversarial attacks on image classifiers. Instead of pulling a prediction toward a target label, the way ordinary knowledge distillation does, IKD pushes a model's prediction on a manipulated image as far as possible from its own prediction on the clean version of that image. The loss function can be built from cross-entropy or KL divergence interchangeably - the paper shows the two produce identical gradients up to a constant, so the choice doesn't matter - but swapping in mean squared error instead noticeably hurts results, since it measures distance in output-probability space differently. Tested on ImageNet against convolutional networks, vision transformers, and models with built-in defenses, IKD improved how well attacks crafted on one model transferred to fool a different one.\n\nTransfer-based attacks matter because they skip the need for direct access to a target system - an attacker trains against a stand-in model and hopes the trick generalizes, which is precisely the threat model for production image-recognition systems that don't expose their internals. The paper backs this up with an information-geometric argument tying IKD's gains to overlap between the stand-in and target model's sensitivity landscapes, which is a more rigorous explanation than the trial-and-error tuning that usually accompanies transfer-attack papers.\n\nThe code is public on GitHub, so anyone building or auditing an image classifier can go check whether their defenses hold up against it - academic adversarial-attack papers have a habit of aging well in a controlled benchmark and less well against a patched, determined, real-world target.","[\"adversarial attacks\",\"ai security\",\"computer vision\",\"arxiv\"]","2026-09-18T04:00:00.000Z","2026-09-18T23:47:10.064Z","2026-09-18T23:47:22.012Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"publisher-r1","publisher",1,"The body claims IKD's soft-label objective is 'mathematically equivalent' to standard cross-entropy\u002FKL approaches and 'produces the same optimization path either way,' which directly contradicts the article's central claim that IKD is a novel technique that improves transferability over those standard approaches.","resolved","security",[32,33,34,35],"adversarial attacks","ai security","computer vision","arxiv",[37],{"name":38,"url":39},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2502.17003",0,{"sections":42},[43,47,50,55,60,64,68,73,77,82,87,92,97,102],{"name":44,"slug":45,"count":46,"latest_published_at":18},"AI","ai",4082,{"name":48,"slug":30,"count":49,"latest_published_at":18},"Security",661,{"name":51,"slug":52,"count":53,"latest_published_at":54},"Policy","policy",339,"2026-09-17T12:00:00.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":18},"Hardware","hardware",155,{"name":65,"slug":66,"count":67,"latest_published_at":18},"Science","science",125,{"name":69,"slug":70,"count":71,"latest_published_at":72},"Consumer Tech","consumer-tech",99,"2026-09-09T17:27:33.000Z",{"name":74,"slug":75,"count":76,"latest_published_at":18},"Dev Tools","dev-tools",78,{"name":78,"slug":79,"count":80,"latest_published_at":81},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Startups","startups",55,"2026-09-09T23:14:29.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"General","general",41,"2026-09-08T01:57:23.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]