σ-zero: Gradient-based Optimization of ℓ0-norm Adversarial Examples
Antonio Emanuele Cinà, Francesco Villani, Maura Pintor, Lea Schönherr, Battista Biggio, Marcello Pelillo
Abstract
Evaluating the adversarial robustness of deep networks to gradient-based attacks is challenging. While most attacks consider ω 2 -and ω → -norm constraints to craft input perturbations, only a few investigate sparse ω 1 -and ω 0 -norm attacks. In particular, ω 0 -norm attacks remain the least studied due to the inherent complexity of optimizing over a non-convex and non-differentiable constraint. However, evaluating adversarial robustness under these attacks could reveal weaknesses otherwise left untested with more conventional ω 2 -and ω → -norm attacks. In this work, we propose a novel ω 0 -norm attack, called ε-zero, which leverages a differentiable approximation of the ω 0 norm to facilitate gradient-based optimization, and an adaptive projection operator to dynamically adjust the trade-off between loss minimization and perturbation sparsity. Extensive evaluations using MNIST, CIFAR10, and ImageNet datasets, involving robust and non-robust models, show that ε-zero finds minimum ω 0 -norm adversarial examples without requiring any time-consuming hyperparameter tuning, and that it outperforms all competing sparse attacks in terms of success rate, perturbation size, and efficiency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution GeneralizationDan Hendrycks, Steven Basart, Norman Mu, Saurav Kadavath et al.ICCV 2021 · 2,294 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Do Adversarially Robust ImageNet Models Transfer Better?Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor et al.NeurIPS 2020 · 506 citations
- Improving Robustness using Generated DataSven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg et al.NeurIPS 2021 · 384 citations
Related papers
- Towards Efficient Training and Evaluation of Robust Models against l0 Bounded Adversarial PerturbationsXuyang Zhong, Yixiao Huang, Chen LiuICML 2024 · 3 citations
- Sparse and Imperceptible Adversarial Attack via a Homotopy AlgorithmMingkang Zhu, Tianlong Chen, Zhangyang WangICML 2021 · 33 citations
- Fast Minimum-norm Adversarial Attacks through Adaptive Norm ConstraintsMaura Pintor, Fabio Roli, Wieland Brendel, Battista BiggioNeurIPS 2021 · 94 citations
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 228 citations
- GSE: Group-wise Sparse and Explainable Adversarial AttacksShpresim Sadiku, Moritz Wagner, Sebastian PokuttaICLR 2025
