@inproceedings{DBLP:conf/iclr/LiuCLS17,
author = {Liu, Yanpei and Chen, Xinyun and Liu, Chang and Song, Dawn},
booktitle = {5th International Conference on Learning Representations, {\{}ICLR{\}} 2017, Toulon, France, April 24-26, 2017, Conference Track Proceedings},
publisher = {OpenReview.net},
title = {{Delving into Transferable Adversarial Examples and Black-box Attacks}},
url = {https://openreview.net/forum?id=Sys6GJqxl},
year = {2017}
}
Overall, they proposed an ensemble-based method to generate transferable adversarial examples, which is an intuitive way. And they provided some geometric insights and I am not very clear about that.
this may be helpful.