CosPGD: an efficient white-box adversarial attack for pixel-wise prediction tasks
Shashank Agnihotri, Steffen Jung, Margret Keuper
Abstract
While neural networks allow highly accurate predictions in many tasks, their lack of robustness towards even slight input perturbations often hampers their deployment. Adversarial attacks such as the seminal projected gradient descent (PGD) offer an effective means to evaluate a model's robustness and dedicated solutions have been proposed for attacks on semantic segmentation or optical flow estimation. While they attempt to increase the attack's efficiency, a further objective is to balance its effect, so that it acts on the entire image domain instead of isolated point-wise predictions. This often comes at the cost of optimization stability and thus efficiency. Here, we propose CosPGD, an attack that encourages more balanced errors over the entire image domain while increasing the attack's overall efficiency. To this end, CosPGD leverages a simple alignment score computed from any pixel-wise prediction and its target to scale the loss in a smooth and fully differentiable way. It leads to efficient evaluations of a model's robustness for semantic segmentation as well as regression models (such as optical flow, disparity estimation, or image restoration), and it allows it to outperform the previous SotA attack on semantic segmentation. We provide code for the CosPGD algorithm and example usage at https://github.com/shashankskagnihotri/cospgd.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9467a27d-26da-455e-9cd6-3936c392a789Cited by top-tier papers6
- RobustSpring: Benchmarking Robustness to Image Corruptions for Optical Flow, Scene Flow and StereoVictor Oei, Jenny Schmalfuss, Lukas Mehl, Madlen Bartsch et al.ICLR 2026 · 9 citations
- PEARL: Preprocessing Enhanced Adversarial Robust Learning of Image Deraining for Semantic SegmentationXianghao Jiao, Yaohua Liu, Jiaxin Gao, Xinyuan Chu et al.ACM MM 2023 · 7 citations
- AAKR: Adversarial Attack-based Knowledge Retention for Continual Semantic SegmentationZhidong Yu, Xiaoman Liu, Jiajun Hu, Zhenbo Shi et al.AAAI 2025 · 1 citation
- Towards Better Robustness Against Natural Corruptions in Document Tampering LocalizationHuiru Shao, Kaizhu Huang, Wei Wang, Xiaowei Huang et al.AAAI 2025 · 1 citation
- Attacks on Continual Semantic Segmentation by Perturbing Incremental SamplesZhidong Yu, Wei Yang, Xike Xie, Zhenbo ShiAAAI 2024 · 1 citation
Builds on17
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- SegFormer: Simple and Efficient Design for Semantic Segmentation with TransformersEnze Xie, Wenhai Wang, Zhiding Yu, Anima Anandkumar et al.NeurIPS 2021 · 9,661 citations
- A ConvNet for the 2020sZhuang Liu, Hanzi Mao, Chao-Yuan Wu, Christoph Feichtenhofer et al.CVPR 2022 · 6,782 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
Related papers
- RP-PGD: Boosting Segmentation Robustness with a Region-and-Prototype Based Adversarial AttackYuxuan Zhang, Zhenbo Shi, Shuchang Wang, Wei Yang et al.AAAI 2025 · 4 citations
- Stop Walking in Circles! Bailing Out Early in Projected Gradient DescentPhilip Doldo, Derek Everett, Amol Khanna, André T. Nguyen et al.CVPR 2025
- BadPart: Unified Black-box Adversarial Patch Attacks against Pixel-wise Regression TasksZhiyuan Cheng, Zhaoyi Liu, Tengda Guo, Shiwei Feng et al.ICML 2024 · 10 citations
- Guided Adversarial Attack for Evaluating and Enhancing Adversarial DefensesGaurang Sriramanan, Sravanti Addepalli, Arya Baburaj, Venkatesh Babu R.NeurIPS 2020 · 123 citations
- Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image ClassifiersFrancesco Croce, Matthias HeinICML 2021 · 68 citations
