Demystifying the Adversarial Robustness of Random Transformation Defenses
Chawin Sitawarin, Zachary J. Golan-Strieb, David A. Wagner
Abstract
Neural networks’ lack of robustness against attacks raises concerns in security-sensitive settings such as autonomous vehicles. While many coun-termeasures may look promising, only a few with-stand rigorous evaluation. Defenses using random transformations (RT) have shown impressive results, particularly BaRT (Raff et al., 2019) on ImageNet. However, this type of defense has not been rigorously evaluated, leaving its robustness properties poorly understood. Their stochastic properties make evaluation more challenging and render many proposed attacks on deterministic models inapplicable. First, we show that the BPDA attack (Athalye et al., 2018a) used in BaRT’s evaluation is ineffective and likely over-estimates its robustness. We then attempt to con-struct the strongest possible RT defense through the informed selection of transformations and Bayesian optimization for tuning their parameters. Furthermore, we create the strongest possible attack to evaluate our RT defense. Our new attack vastly outperforms the baseline, reducing the accuracy by 83% compared to the 19% re-duction by the commonly used EoT attack ( 4 . 3 × improvement). Our result indicates that the RT defense on Imagenette dataset (a ten-class subset of ImageNet) is not robust against adversarial examples. Extending the study further, we use our new attack to adversarially train RT defense (called AdvRT), resulting in a large robustness gain. Code is available at https://github.com/wagner-group/demystify-random-transform.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 00f0279d-b422-47b1-a08d-084830a0f1faCited by top-tier papers6
- On the Limitations of Stochastic Pre-processing DefensesYue Gao, Ilia Shumailov, Kassem Fawaz, Nicolas PapernotNeurIPS 2022 · 35 citations
- Adversarial Illusions in Multi-Modal EmbeddingsTingwei Zhang, Rishi D. Jha, Eugene Bagdasaryan, Vitaly ShmatikovUSENIX Security 2024 · 32 citations
- Be Your Own Neighborhood: Detecting Adversarial Examples by the Neighborhood Relations Built on Self-Supervised LearningZhiyuan He, Yijun Yang, Pin-Yu Chen, Qiang Xu et al.ICML 2024 · 11 citations
- Preprocessors Matter! Realistic Decision-Based Attacks on Machine Learning SystemsChawin Sitawarin, Florian Tramèr, Nicholas CarliniICML 2023 · 10 citations
- Improving Generalization and Robustness in SNNs Through Signed Rate Encoding and Sparse Encoding AttacksBhaskar Mukhoty, Hilal AlQuabeh, Bin GuICLR 2025
Builds on9
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNetsDongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey et al.ICLR 2020 · 357 citations
Related papers
- Improving the Transferability of Adversarial Samples With Adversarial TransformationsWeibin Wu, Yuxin Su, Michael R. Lyu, Irwin KingCVPR 2021
- Adversarial Training on Purification (AToP): Advancing Both Robustness and GeneralizationGuang Lin, Chao Li, Jianhai Zhang, Toshihisa Tanaka et al.ICLR 2024 · 25 citations
- Discrete Adversarial Attack to Models of CodeFengjuan Gao, Yu Wang, Ke WangPLDI 2023 · 23 citations
- Enhancing Transformation-Based Defenses Against Adversarial Attacks with a Distribution ClassifierConnie Kou, Hwee Kuan Lee, Ee-Chien Chang, Teck Khim NgICLR 2020 · 22 citations
- MORA: Improving Ensemble Robustness Evaluation with Model Reweighing AttackYunrui Yu, Xitong Gao, Cheng-Zhong XuNeurIPS 2022 · 14 citations
