Lune

ICML2021Top-tier venue

Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image Classifiers

Francesco Croce, Matthias Hein

2021Year
68Citations
27Top-tier citations

Abstract

We show that when taking into account also the image domain [0,1]d[0,1]^d, established l1l_1-projected gradient descent (PGD) attacks are suboptimal as they do not consider that the effective threat model is the intersection of the l1l_1-ball and [0,1]d[0,1]^d. We study the expected sparsity of the steepest descent step for this effective threat model and show that the exact projection onto this set is computationally feasible and yields better performance. Moreover, we propose an adaptive form of PGD which is highly effective even with a small budget of iterations. Our resulting l1l_1-APGD is a strong white-box attack showing that prior works overestimated their l1l_1-robustness. Using l1l_1-APGD for adversarial training we get a robust classifier with SOTA l1l_1-robustness. Finally, we combine l1l_1-APGD and an adaptation of the Square Attack to l1l_1 into l1l_1-AutoAttack, an ensemble of attacks which reliably assesses adversarial robustness for the threat model of l1l_1-ball intersected with [0,1]d[0,1]^d.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 830ce721-fa57-45c4-8475-c93fd98efa88

Cited by top-tier papers27

Ask how each one uses it

Builds on11

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines