File size: 5,298 Bytes
3c6934e | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 | ---
license: mit
library_name: pytorch
tags:
- adversarial-robustness
- adversarial-examples
- transfer-attack
- image-classification
datasets:
- cifar10
- cifar100
---
# Scissors Effect: naturally trained surrogates
The five checkpoints used as the *standard* (naturally trained) surrogates in
**"The Scissors Effect: When Resize-Based Input Diversity Helps or Hurts Transfer
Attacks"**, published in *Transactions on Machine Learning Research* (2026).
Every other model in that paper comes from the RobustBench zoo, torchvision, or
`open_clip` and downloads on its own. These five do not exist anywhere else, and
without them the CIFAR-10 standard side and the whole CIFAR-100 experiment cannot
be reproduced without retraining. That is the only reason this repository exists.
- **Paper:** [arXiv:2606.22516](https://arxiv.org/abs/2606.22516) · [OpenReview](https://openreview.net/forum?id=b4pCcgJM0M)
- **Code:** [github.com/Avalon-S/ScissorsEffect](https://github.com/Avalon-S/ScissorsEffect)
- **Project page:** [avalon-s.github.io/ScissorsEffect](https://avalon-s.github.io/ScissorsEffect/)
## The checkpoints
| File | Dataset | Architecture | Clean accuracy | Size | Train time |
|---|---|---|---|---|---|
| `c10_resnet18.pt` | CIFAR-10 | ResNet-18 | 94.92% | 42.7 MB | 31 min |
| `c10_resnet50.pt` | CIFAR-10 | ResNet-50 | 94.66% | 90.0 MB | 69 min |
| `c10_vgg16.pt` | CIFAR-10 | VGG-16 | 93.82% | 56.2 MB | 22 min |
| `c10_densenet121.pt` | CIFAR-10 | DenseNet-121 | 95.39% | 27.1 MB | 111 min |
| `Standard_WRN28_10.pt` | CIFAR-100 | WRN-28-10 | 81.07% | 139.5 MB | 2.5 h |
Times are for a single RTX 4090. The paper quotes the CIFAR-10 four as reaching
93.8–95.4% clean accuracy, which is the range above.
The architectures are CIFAR variants: 3x3 stem, no initial max-pool, not ImageNet
architectures fed upsampled 32x32 images.
## Two storage formats
This is the one thing worth reading before you load anything.
**The four CIFAR-10 checkpoints are saved wrapped.** The normalisation lives
inside the checkpoint, so the model consumes `[0,1]` images directly. Each is a
dict with `state_dict`, `arch`, `clean_acc` and the training `recipe`.
**The CIFAR-100 checkpoint is a bare state dict** for RobustBench's
`WideResNet(depth=28, num_classes=100, widen_factor=10)`. It carries no
normalisation of its own; the loader applies the CIFAR-100 statistics around it.
Loading either one by hand:
```python
import torch, importlib.util
# --- CIFAR-10: wrapped, consumes [0,1] ---
spec = importlib.util.spec_from_file_location(
"t", "ScissorsEffect/scripts/train_cifar10_standard.py")
m = importlib.util.module_from_spec(spec); spec.loader.exec_module(m)
ck = torch.load("c10_resnet18.pt", map_location="cpu", weights_only=False)
net = m.Normalized(m.BUILDERS[ck["arch"]]())
net.load_state_dict(ck["state_dict"], strict=True)
net.eval() # net(x) with x in [0,1]
# --- CIFAR-100: bare, normalise outside ---
from robustbench.model_zoo.architectures.wide_resnet import WideResNet
sd = torch.load("Standard_WRN28_10.pt", map_location="cpu", weights_only=False)
sd = sd.get("state_dict", sd) if isinstance(sd, dict) else sd
sd = {(k[7:] if k.startswith("module.") else k): v for k, v in sd.items()}
wrn = WideResNet(depth=28, num_classes=100, widen_factor=10)
wrn.load_state_dict(sd, strict=True)
# mean (0.5071, 0.4865, 0.4409), std (0.2673, 0.2564, 0.2762)
```
Through the paper's own code you do not need any of this. Put the files where
`models/loader.py` looks for them and ask for the model by name:
```
<MODEL_ROOT>/cifar10/standard/c10_resnet18.pt
<MODEL_ROOT>/cifar10/standard/c10_resnet50.pt
<MODEL_ROOT>/cifar10/standard/c10_vgg16.pt
<MODEL_ROOT>/cifar10/standard/c10_densenet121.pt
<MODEL_ROOT>/cifar100/Linf/Standard_WRN28_10.pt
```
Loading refuses a partially initialised network and re-asserts the stored clean
accuracy, so a truncated download raises instead of quietly degrading a result.
## Verify the download
```
sha256sum -c SHA256SUMS
```
## How they were trained
One recipe for all five: SGD (lr 0.1, momentum 0.9, weight decay 5e-4),
MultiStepLR at epochs [100, 150] with gamma 0.1, 200 epochs, batch 128,
`RandomCrop(32, padding=4)` + `RandomHorizontalFlip`. No label smoothing, no
mixup or cutmix, no EMA. The run aborts if a model finishes below a
clean-accuracy floor, so a failed model never reaches the experiments.
Reproduce with the script in the code repository:
```
python scripts/train_cifar10_standard.py # the CIFAR-10 four
python scripts/train_cifar10_standard.py --dataset cifar100 # the WRN-28-10
```
`provenance/` holds the records the training runs wrote themselves:
`cifar10_training_summary.json` (recipe, per-model accuracy and wall-clock),
`cifar100_training_summary.txt`, and the per-epoch `cifar100_training_log.txt`.
## Citation
```bibtex
@article{jiang2026scissors,
title = {The Scissors Effect: When Resize-Based Input Diversity Helps or Hurts Transfer Attacks},
author = {Jiang, Yuhang and Chen, Xiaojing},
journal = {Transactions on Machine Learning Research},
year = {2026},
url = {https://openreview.net/forum?id=b4pCcgJM0M}
}
```
## License
MIT, matching the code repository. The paper is published by TMLR under CC BY 4.0.
|