I'm curious if the adversarial CA reprogramming techniques are similarly transferable. That is, do the adversarial CA and/or the adversarial perturbation matrix transfer to separate CAs (trained on the same task) with different weights or architectures than the original CA that was targeted?
Is this something you've explored or plan to?