Scissors Effect: naturally trained surrogates

The five checkpoints used as the standard (naturally trained) surrogates in "The Scissors Effect: When Resize-Based Input Diversity Helps or Hurts Transfer Attacks", published in Transactions on Machine Learning Research (2026).

Every other model in that paper comes from the RobustBench zoo, torchvision, or open_clip and downloads on its own. These five do not exist anywhere else, and without them the CIFAR-10 standard side and the whole CIFAR-100 experiment cannot be reproduced without retraining. That is the only reason this repository exists.

The checkpoints

File Dataset Architecture Clean accuracy Size Train time
c10_resnet18.pt CIFAR-10 ResNet-18 94.92% 42.7 MB 31 min
c10_resnet50.pt CIFAR-10 ResNet-50 94.66% 90.0 MB 69 min
c10_vgg16.pt CIFAR-10 VGG-16 93.82% 56.2 MB 22 min
c10_densenet121.pt CIFAR-10 DenseNet-121 95.39% 27.1 MB 111 min
Standard_WRN28_10.pt CIFAR-100 WRN-28-10 81.07% 139.5 MB 2.5 h

Times are for a single RTX 4090. The paper quotes the CIFAR-10 four as reaching 93.8–95.4% clean accuracy, which is the range above.

The architectures are CIFAR variants: 3x3 stem, no initial max-pool, not ImageNet architectures fed upsampled 32x32 images.

Two storage formats

This is the one thing worth reading before you load anything.

The four CIFAR-10 checkpoints are saved wrapped. The normalisation lives inside the checkpoint, so the model consumes [0,1] images directly. Each is a dict with state_dict, arch, clean_acc and the training recipe.

The CIFAR-100 checkpoint is a bare state dict for RobustBench's WideResNet(depth=28, num_classes=100, widen_factor=10). It carries no normalisation of its own; the loader applies the CIFAR-100 statistics around it.

Loading either one by hand:

import torch, importlib.util

# --- CIFAR-10: wrapped, consumes [0,1] ---
spec = importlib.util.spec_from_file_location(
    "t", "ScissorsEffect/scripts/train_cifar10_standard.py")
m = importlib.util.module_from_spec(spec); spec.loader.exec_module(m)

ck = torch.load("c10_resnet18.pt", map_location="cpu", weights_only=False)
net = m.Normalized(m.BUILDERS[ck["arch"]]())
net.load_state_dict(ck["state_dict"], strict=True)
net.eval()                       # net(x) with x in [0,1]

# --- CIFAR-100: bare, normalise outside ---
from robustbench.model_zoo.architectures.wide_resnet import WideResNet

sd = torch.load("Standard_WRN28_10.pt", map_location="cpu", weights_only=False)
sd = sd.get("state_dict", sd) if isinstance(sd, dict) else sd
sd = {(k[7:] if k.startswith("module.") else k): v for k, v in sd.items()}
wrn = WideResNet(depth=28, num_classes=100, widen_factor=10)
wrn.load_state_dict(sd, strict=True)
# mean (0.5071, 0.4865, 0.4409), std (0.2673, 0.2564, 0.2762)

Through the paper's own code you do not need any of this. Put the files where models/loader.py looks for them and ask for the model by name:

<MODEL_ROOT>/cifar10/standard/c10_resnet18.pt
<MODEL_ROOT>/cifar10/standard/c10_resnet50.pt
<MODEL_ROOT>/cifar10/standard/c10_vgg16.pt
<MODEL_ROOT>/cifar10/standard/c10_densenet121.pt
<MODEL_ROOT>/cifar100/Linf/Standard_WRN28_10.pt

Loading refuses a partially initialised network and re-asserts the stored clean accuracy, so a truncated download raises instead of quietly degrading a result.

Verify the download

sha256sum -c SHA256SUMS

How they were trained

One recipe for all five: SGD (lr 0.1, momentum 0.9, weight decay 5e-4), MultiStepLR at epochs [100, 150] with gamma 0.1, 200 epochs, batch 128, RandomCrop(32, padding=4) + RandomHorizontalFlip. No label smoothing, no mixup or cutmix, no EMA. The run aborts if a model finishes below a clean-accuracy floor, so a failed model never reaches the experiments.

Reproduce with the script in the code repository:

python scripts/train_cifar10_standard.py                      # the CIFAR-10 four
python scripts/train_cifar10_standard.py --dataset cifar100   # the WRN-28-10

provenance/ holds the records the training runs wrote themselves: cifar10_training_summary.json (recipe, per-model accuracy and wall-clock), cifar100_training_summary.txt, and the per-epoch cifar100_training_log.txt.

Citation

@article{jiang2026scissors,
  title   = {The Scissors Effect: When Resize-Based Input Diversity Helps or Hurts Transfer Attacks},
  author  = {Jiang, Yuhang and Chen, Xiaojing},
  journal = {Transactions on Machine Learning Research},
  year    = {2026},
  url     = {https://openreview.net/forum?id=b4pCcgJM0M}
}

License

MIT, matching the code repository. The paper is published by TMLR under CC BY 4.0.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Datasets used to train Avalon-S/ScissorsEffect

Paper for Avalon-S/ScissorsEffect