A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses
Ambar Pal, René Vidal
Abstract
Research in adversarial learning follows a cat and mouse game between attackers and defenders where attacks are proposed, they are mitigated by new defenses, and subsequently new attacks are proposed that break earlier defenses, and so on. However, it has remained unclear as to whether there are conditions under which no better attacks or defenses can be proposed. In this paper, we propose a game-theoretic framework for studying attacks and defenses which exist in equilibrium. Under a locally linear decision boundary model for the underlying binary classifier, we prove that the Fast Gradient Method attack and the Randomized Smoothing defense form a Nash Equilibrium. We then show how this equilibrium defense can be approximated given finitely many samples from a data-generating distribution, and derive a generalization bound for the performance of our approximation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8e5bb4c5-b981-4e9a-97b4-11925be8d83eCited by top-tier papers7
- Towards a Unified Game-Theoretic View of Adversarial Perturbations and RobustnessJie Ren, Die Zhang, Yisen Wang, Lu Chen et al.NeurIPS 2021 · 27 citations
- Balance, Imbalance, and Rebalance: Understanding Robust Overfitting from a Minimax Game PerspectiveYifei Wang, Liangchen Li, Jiansheng Yang, Zhouchen Lin et al.NeurIPS 2023 · 26 citations
- The Good, the Bad and the Ugly: Meta-Analysis of Watermarks, Transferable Attacks and Adversarial DefensesGreg Gluch, Berkant Turan, Sai Ganesh Nagarajan, Sebastian PokuttaNeurIPS 2025
- Rethinking the Adversarial Robustness of Multi-Exit Neural Networks in an Attack-Defense GameKeyizhi Xu, Chi Zhang, Zhan Chen, Zhongyuan Wang et al.CVPR 2025
- Adversarial Training for Defense Against Label Poisoning AttacksMelis Ilayda Bal, Volkan Cevher, Michael MuehlebachICLR 2025
Builds on3
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
Related papers
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre et al.ICML 2020 · 66 citations
- Mixed Nash Equilibria in the Adversarial Examples GameLaurent Meunier, Meyer Scetbon, Rafael Pinot, Jamal Atif et al.ICML 2021 · 32 citations
- On the Generalization Analysis of Adversarial LearningWaleed Mustafa, Yunwen Lei, Marius KloftICML 2022 · 20 citations
- Smoothed Embeddings for Certified Few-Shot LearningMikhail Pautov, Olesya Kuznetsova, Nurislam Tursynbek, Aleksandr Petiushko et al.NeurIPS 2022 · 10 citations
- Randomized Smoothing of All Shapes and SizesGreg Yang, Tony Duan, J. Edward Hu, Hadi Salman et al.ICML 2020 · 237 citations
