A Branch and Bound Framework for Stronger Adversarial Attacks of ReLU Networks
Huan Zhang, Shiqi Wang, Kaidi Xu, Yihan Wang, Suman Jana, Cho-Jui Hsieh, J. Zico Kolter
Abstract
Strong adversarial attacks are important for evaluating the true robustness of deep neural networks. Most existing attacks search in the input space, e.g., using gradient descent, and may miss adversarial examples due to non-convexity. In this work, we systematically search adversarial examples in the activation space of ReLU networks to tackle hard instances where none of the existing adversarial attacks succeed. Unfortunately, searching the activation space typically relies on generic mixed integer programming (MIP) solvers and is limited to small networks and easy problem instances. To improve scalability and practicability, we use branch and bound (BaB) with specialized GPU-based bound propagation methods, and propose a top-down beam-search approach to quickly identify the subspace that may contain adversarial examples. Moreover, we build an adversarial candidates pool using cheap attacks to further assist the search in activation space via diving techniques and a bottom-up large neighborhood search. Our adversarial attack framework, BaB-Attack, opens up a new opportunity for designing novel adversarial attacks not limited to searching the input space, and enables us to borrow techniques from integer programming theory and neural network verification. In experiments, we can successfully generate adversarial examples when existing attacks on input space fail. Compared to off-the-shelf MIP solver based attacks that requires significant computations, we outperform in both success rates and efficiency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e3a9f738-ca28-4ac7-bda7-28576d15994eCited by top-tier papers8
- An Efficient Membership Inference Attack for the Diffusion Model by Proximal InitializationFei Kong, Jinhao Duan, Ruipeng Ma, Heng Tao Shen et al.ICLR 2024 · 55 citations
- SEEV: Synthesis with Efficient Exact Verification for ReLU Neural Barrier FunctionsHongchao Zhang, Zhizhen Qin, Sicun Gao, Andrew ClarkNeurIPS 2024 · 17 citations
- Detecting Brittle Decisions for Free: Leveraging Margin Consistency in Deep Robust ClassifiersJonas Ngnawé, Sabyasachi Sahoo, Yann Pequignot, Frédéric Precioso et al.NeurIPS 2024 · 12 citations
- ARQ: A Mixed-Precision Quantization Framework for Accurate and Certifiably Robust DNNsYuchen Yang, Yifan Zhao, Shubham Ugare, Gagandeep Singh et al.ISSTA 2026 · 2 citations
- Activation-Descent Regularization for Input Optimization of ReLU NetworksHongzhan Yu, Sicun GaoICML 2024 · 1 citation
Builds on11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
- Formal Security Analysis of Neural Networks using Symbolic IntervalsShiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang et al.USENIX Security 2018 · 523 citations
- Fast and Complete: Enabling Complete Neural Network Verification with Rapid and Massively Parallel Incomplete VerifiersKaidi Xu, Huan Zhang, Shiqi Wang, Yihan Wang et al.ICLR 2021 · 250 citations
Related papers
- Mining Verdict Boundaries for Neural Network VerificationJiawei Ren, Guanqin Zhang, Zhenya Zhang, Yulei SuiFM 2026
- Verifying message-passing neural networks via topology-based bounds tighteningChristopher Hojny, Shiqiang Zhang, Juan S. Campos, Ruth MisenerICML 2024 · 15 citations
- LEVIS: Large Exact Verifiable Input Spaces for Neural NetworksMohamad Fares El Hajj Chehade, Wenting Li, Brian Wesley Bell, Russell Bent et al.ICML 2025
- Verifying Properties of Binary Neural Networks Using Sparse Polynomial OptimizationJianting Yang, Srecko Ðurasinovic, Jean B. Lasserre, Victor Magron et al.ICLR 2025
- General Cutting Planes for Bound-Propagation-Based Neural Network VerificationHuan Zhang, Shiqi Wang, Kaidi Xu, Linyi Li et al.NeurIPS 2022 · 154 citations
