Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image Classifiers
Francesco Croce, Matthias Hein
Abstract
We show that when taking into account also the image domain , established -projected gradient descent (PGD) attacks are suboptimal as they do not consider that the effective threat model is the intersection of the -ball and . We study the expected sparsity of the steepest descent step for this effective threat model and show that the exact projection onto this set is computationally feasible and yields better performance. Moreover, we propose an adaptive form of PGD which is highly effective even with a small budget of iterations. Our resulting -APGD is a strong white-box attack showing that prior works overestimated their -robustness. Using -APGD for adversarial training we get a robust classifier with SOTA -robustness. Finally, we combine -APGD and an adaptation of the Square Attack to into -AutoAttack, an ensemble of attacks which reliably assesses adversarial robustness for the threat model of -ball intersected with .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 830ce721-fa57-45c4-8475-c93fd98efa88Cited by top-tier papers27
- Sparse-RS: A Versatile Framework for Query-Efficient Sparse Black-Box Adversarial AttacksFrancesco Croce, Maksym Andriushchenko, Naman D. Singh, Nicolas Flammarion et al.AAAI 2022 · 135 citations
- Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat ModelsNaman Deep Singh, Francesco Croce, Matthias HeinNeurIPS 2023 · 119 citations
- Learning to Generate Noise for Multi-Attack RobustnessDivyam Madaan, Jinwoo Shin, Sung Ju HwangICML 2021 · 31 citations
- On the Duality Between Sharpness-Aware Minimization and Adversarial TrainingYihao Zhang, Hangzhou He, Jingyu Zhu, Huanran Chen et al.ICML 2024 · 29 citations
- Adversarial Robustness against Multiple and Single lp-Threat Models via Quick Fine-Tuning of Robust ClassifiersFrancesco Croce, Matthias HeinICML 2022 · 26 citations
Builds on11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
Related papers
- Towards Efficient Training and Evaluation of Robust Models against l0 Bounded Adversarial PerturbationsXuyang Zhong, Yixiao Huang, Chen LiuICML 2024 · 3 citations
- Subspace Adversarial TrainingTao Li, Yingwen Wu, Sizhe Chen, Kun Fang et al.CVPR 2022 · 59 citations
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 228 citations
- Robustness Guarantees for Adversarially Trained Neural NetworksPoorya Mianjy, Raman AroraNeurIPS 2023 · 4 citations
- Towards Stable and Efficient Adversarial Training against l1 Bounded Adversarial AttacksYulun Jiang, Chen Liu, Zhichao Huang, Mathieu Salzmann et al.ICML 2023 · 13 citations
