Characterizing the Evasion Attackability of Multi-label Classifiers
Zhuo Yang, Yufei Han, Xiangliang Zhang
Abstract
Evasion attack in multi-label learning systems is an interesting, widely witnessed, yet rarely explored research topic. Characterizing the crucial factors determining the attackability of the multi-label adversarial threat is the key to interpret the origin of the adversarial vulnerability and to understand how to mitigate it. Our study is inspired by the theory of adversarial risk bound. We associate the attackability of a targeted multi-label classifier with the regularity of the classifier and the training data distribution. Beyond the theoretical attackability analysis, we further propose an efficient empirical attackability estimator via greedy label space exploration. It provides provably computational efficiency and approximation accuracy. Substantial experimental results on real-world datasets validate the unveiled attackability factors and the effectiveness of the proposed empirical attackability indicator.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 826c4e94-0714-49ab-8ddb-be8a0b4b022cCited by top-tier papers3
- MultiGuard: Provably Robust Multi-label Classification against Adversarial ExamplesJinyuan Jia, Wenjie Qu, Neil Zhenqiang GongNeurIPS 2022 · 22 citations
- Semantic-Aware Multi-Label Adversarial AttacksHassan Mahmood, Ehsan ElhamifarCVPR 2024 · 3 citations
- Compositional Targeted Multi-Label Universal PerturbationsHassan Mahmood, Ehsan ElhamifarCVPR 2025
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- The Many Kinds of Creepware Used for Interpersonal AttacksKevin A. Roundy, Paula Barmaimon Mendelberg, Nicola Dell, Damon McCoy et al.S&P 2020 · 46 citations
- Certifiable Robustness of Graph Convolutional Networks under Structure PerturbationsDaniel Zügner, Stephan GünnemannKDD 2020 · 44 citations
Related papers
- Attackability Characterization of Adversarial Evasion Attack on Discrete DataYutong Wang, Yufei Han, Hongyan Bao, Yun Shen et al.KDD 2020 · 13 citations
- Consistent Adversarially Robust Linear Classification: Non-Parametric SettingElvis DohmatobICML 2024 · 2 citations
- Towards Understanding the Robustness Against Evasion Attack on Categorical DataHongyan Bao, Yufei Han, Yujun Zhou, Yun Shen et al.ICLR 2022 · 10 citations
- When Measures are Unreliable: Imperceptible Adversarial Perturbations toward Top-k Multi-Label LearningYuchen Sun, Qianqian Xu, Zitai Wang, Qingming HuangACM MM 2023 · 2 citations
- Attacks on Online Learners: a Teacher-Student AnalysisRiccardo Giuseppe Margiotta, Sebastian Goldt, Guido SanguinettiNeurIPS 2023 · 2 citations
