Adversarial images targeting an image classifier have been shown to be transferable to separately trained models (i.e., models with different weights or different architectures relative to the model for which the adversarial image was constructed to target).
I'm curious if the adversarial CA reprogramming techniques are similarly transferable. That is, do the adversarial CA and/or the adversarial perturbation matrix transfer to separate CAs (trained on the same task) with different weights or architectures than the original CA that was targeted?