How Many Perturbations Break This Model? Evaluating Robustness Beyond Adversarial Accuracy
Raphaël Olivier, Bhiksha Raj
摘要
Robustness to adversarial attacks is typically evaluated with adversarial accuracy. While essential, this metric does not capture all aspects of robustness and in particular leaves out the question of how many perturbations can be found for each point. In this work, we introduce an alternative approach, adversarial sparsity, which quantifies how difficult it is to find a successful perturbation given both an input point and a constraint on the direction of the perturbation. We show that sparsity provides valuable insight into neural networks in multiple ways: for instance, it illustrates important differences between current state-of-the-art robust models them that accuracy analysis does not, and suggests approaches for improving their robustness. When applying "broken" defenses effective against weak attacks but not strong ones, sparsity can discriminate between the "totally ineffective" and the "partially effective" defenses. Finally, with sparsity we can measure increases in robustness that do not affect accuracy: we show for example that data augmentation can by itself increase adversarial robustness, without using adversarial training.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- GREAT Score: Global Robustness Evaluation of Adversarial Perturbation using Generative ModelsZaitang Li, Pin-Yu Chen, Tsung-Yi HoNeurIPS 2024 · 被引用 8 次
- Quadratic Upper Bound for Boosting RobustnessEuijin You, Hyang-Won LeeICML 2025
它引用的顶会 Paper12
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- Do Vision Transformers See Like Convolutional Neural Networks?Maithra Raghu, Thomas Unterthiner, Simon Kornblith, Chiyuan Zhang 等NeurIPS 2021 · 被引用 1,553 次
相关 Paper
- SuperDeepFool: a new fast and accurate minimal adversarial attackAlireza Abdollahpour, Mahed Abroshan, Seyed-Mohsen Moosavi-DezfooliNeurIPS 2024 · 被引用 11 次
- Nasty Adversarial Training: A Probability Sparsity Perspective for Robustness EnhancementYuhang Zhou, Zhongyun Hua, Zhaoquan Gu, Keke Tang 等ICLR 2026
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 被引用 1,026 次
- Are Defenses for Graph Neural Networks Robust?Felix Mujkanovic, Simon Geisler, Stephan Günnemann, Aleksandar BojchevskiNeurIPS 2022 · 被引用 79 次
- Indicators of Attack Failure: Debugging and Improving Optimization of Adversarial ExamplesMaura Pintor, Luca Demetrio, Angelo Sotgiu, Ambra Demontis 等NeurIPS 2022 · 被引用 39 次
