Adversarial vulnerability for any classifier

Alhussein Fawzi, Hamza Fawzi, Omar Fawzi

Neural Information Processing Systems 

We prove the existence of adversarial perturbations that transfer across different classifiers.