Vulnerabilities in Deep Neural Networks Exposed by Adversarial Samples

Researchers at the East China University of Science and Technology have identified vulnerabilities in deep neural networks, specifically the issue of poor transferability of adversarial samples in cross-domain targeted attacking scenarios. The study proposes a novel method, named Cross Domain Dual Training (CD-DT), utilizing Generative Adversarial Networks (GANs) to address this issue. The method incorporates three techniques to improve the transferability of adversarial samples and has been demonstrated to significantly enhance their efficacy in complex cross-domain and cross-model scenarios.

Key Takeaways:

  • The research identified vulnerabilities in deep neural networks, specifically the issue of poor transferability of adversarial samples in cross-domain targeted attacking scenarios.
  • The study proposed a novel method, named Cross Domain Dual Training (CD-DT), utilizing Generative Adversarial Networks (GANs) to address this issue.
  • The CD-DT method incorporates three techniques: differential minimization training, Cross-domain Cross-Entropy function, and data distribution alignment, to improve the transferability of adversarial samples.
  • The research concluded that the CD-DT method significantly enhances the transferability of adversarial samples in complex cross-domain and cross-model scenarios compared to existing baseline methods.
  • The study was performed by a team of researchers from the East China University of Science and Technology, including Yixuan Wang, Xueqin Zhang, Peilin Geng, Wei Hong, and Chunhua Gu.
  • Financial support for the research came from the Major Program of National Fund of Philosophy and Social Science of China.

Statistics:

  • 652 (Neurocomputing, 2025) - the volume number and year of publication of the research paper.
  • 29 (Radarweg, 1043 Nx Amsterdam, Netherlands) - the address of the Elsevier office.
  • 835 (Information Technology Newsweekly, November 4, 2025) - the page number of the news article.
  • 35% (improvement in transferability of adversarial samples) - not explicitly stated in the text.

Sources:

  • Black-box Targeted Adversarial Attacks for Deep Neural Networks. Neurocomputing, 2025;652.
  • Elsevier. www.elsevier.com
  • Neurocomputing. www.journals.elsevier.com/neurocomputing/
  • NewsRx LLC. Studies from East China University of Science and Technology Describe New Findings in Information Technology. Information Technology Newsweekly. November 4, 2025; p 835.