Towards Stable and Efficient Adversarial Training against l1 Bounded Adversarial Attacks
Yulun Jiang, Chen Liu, Zhichao Huang, Mathieu Salzmann, Sabine Süsstrunk
Abstract
We address the problem of stably and efficiently training a deep neural network robust to adversarial perturbations bounded by an l 1 norm. We demonstrate that achieving robustness against l 1bounded perturbations is more challenging than in the l 2 or l ∞ cases, because adversarial training against l 1 -bounded perturbations is more likely to suffer from catastrophic overfitting and yield training instabilities. Our analysis links these issues to the coordinate descent strategy used in existing methods. We address this by introducing Fast-EG-l 1 , an efficient adversarial training algorithm based on Euclidean geometry and free of coordinate descent. Fast-EG-l 1 comes with no additional memory costs and no extra hyper-parameters to tune. Our experimental results on various datasets demonstrate that Fast-EG-l 1 yields the best and most stable robustness against l 1 -bounded adversarial attacks among the methods of comparable computational complexity. Code and the checkpoints are available at https://github.com/IVRL/FastAdvL1 .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 09c2c9fd-7c4e-41c7-b47b-7ed83197583bCited by top-tier papers6
- Brusleattack: a Query-Efficient Score- based Black-Box Sparse Adversarial AttackViet Quoc Vo, Ehsan Abbasnejad, Damith RanasingheICLR 2024 · 14 citations
- Towards Efficient Training and Evaluation of Robust Models against l0 Bounded Adversarial PerturbationsXuyang Zhong, Yixiao Huang, Chen LiuICML 2024 · 3 citations
- Learning Bregman Divergences with Application to RobustnessMohamed-Hicham Leghettas, Markus PüschelNeurIPS 2024
- Understanding and Improving Fast Adversarial Training against Bounded PerturbationsXuyang Zhong, Yixiao Huang, Chen LiuNeurIPS 2025
- σ-zero: Gradient-based Optimization of ℓ0-norm Adversarial ExamplesAntonio Emanuele Cinà, Francesco Villani, Maura Pintor, Lea Schönherr et al.ICLR 2025
Builds on14
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 917 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
- Data Augmentation Can Improve RobustnessSylvestre-Alvise Rebuffi, Sven Gowal, Dan Andrei Calian, Florian Stimberg et al.NeurIPS 2021 · 427 citations
Related papers
- Understanding and Increasing Efficiency of Frank-Wolfe Adversarial TrainingTheodoros Tsiligkaridis, Jay RobertsCVPR 2022 · 6 citations
- Implicit Bias of Gradient Descent based Adversarial Training on Separable DataYan Li, Ethan X. Fang, Huan Xu, Tuo ZhaoICLR 2020 · 40 citations
- Understanding and Improving Fast Adversarial TrainingMaksym Andriushchenko, Nicolas FlammarionNeurIPS 2020 · 366 citations
- Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image ClassifiersFrancesco Croce, Matthias HeinICML 2021 · 68 citations
- Implicit Bias of Adversarial Training for Deep Neural NetworksBochen Lv, Zhanxing ZhuICLR 2022 · 8 citations
