Generating Distributional Adversarial Examples to Evade Statistical Detectors
Yigitcan Kaya, Muhammad Bilal Zafar, Sergül Aydöre, Nathalie Rauschmayr, Krishnaram Kenthapadi
Abstract
Deep neural networks (DNNs) are known to be highly vulnerable to adversarial examples (AEs) that include malicious perturbations. Assumptions about the statistical differences between natural and adversarial inputs are commonplace in many detection techniques. As a best practice, AE detectors are evaluated against adaptive attackers who actively perturb their inputs to avoid detection. Due to the difficulties in designing adaptive attacks, however, recent work suggests that most detectors have incomplete evaluation. We aim to fill this gap by designing a generic adaptive attack against detectors: the statistical indistinguishability attack (SIA). SIA optimizes a novel objective to craft adversarial examples (AEs) that follow the same distribution as the natural inputs with respect to DNN representations. Our objective targets all DNN layers simultaneously as we show that AEs being indistinguishable at one layer might fail to be so at other layers. SIA is formulated around evading distributional detectors that inspect a set of AEs as a whole and is also effective against four individual AE detectors, two dataset shift detectors, and an out-of-distribution sample detector, curated from published works. This suggests that SIA can be a reliable tool for evaluating the security of a range of detectors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b4804adf-d83e-45b2-b44c-12dafdac7b0bCited by top-tier papers3
- Obfuscated Activations Bypass LLM Latent-Space DefensesLuke Bailey, Alex Serrano, Abhay Sheshadri, Mikhail Seleznyov et al.ICLR 2026 · 28 citations
- DistXplore: Distribution-Guided Testing for Evaluating and Enhancing Deep Learning SystemsLongtian Wang, Xiaofei Xie, Xiaoning Du, Meng Tian et al.FSE 2023 · 15 citations
- Deep Learning Models as Moving Targets to Counter Modulation Classification AttacksNaureen Hoque, Hanif RahbariINFOCOM 2024 · 1 citation
Builds on16
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Energy-based Out-of-distribution DetectionWeitang Liu, Xiaoyun Wang, John D. Owens, Yixuan LiNeurIPS 2020 · 2,213 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- ReAct: Out-of-distribution Detection With Rectified ActivationsYiyou Sun, Chuan Guo, Yixuan LiNeurIPS 2021 · 733 citations
Related papers
- Evading DeepFake Detectors via Adversarial Statistical ConsistencyYang Hou, Qing Guo, Yihao Huang, Xiaofei Xie et al.CVPR 2023
- Feature-Indistinguishable Attack to Circumvent Trapdoor-Enabled DefenseChaoxiang He, Bin Benjamin Zhu, Xiaojing Ma, Hai Jin et al.CCS 2021 · 4 citations
- Structure Invariant Transformation for better Adversarial TransferabilityXiaosen Wang, Zeliang Zhang, Jianping ZhangICCV 2023 · 130 citations
- Transferable Perturbations of Deep Feature DistributionsNathan Inkawhich, Kevin J. Liang, Lawrence Carin, Yiran ChenICLR 2020 · 100 citations
- DA³: A Distribution-Aware Adversarial Attack against Language ModelsYibo Wang, Xiangjue Dong, James Caverlee, Philip S. YuEMNLP 2024 · 2 citations
