Practical Evaluation of Adversarial Robustness via Adaptive Auto Attack
Ye Liu, Yaya Cheng, Lianli Gao, Xianglong Liu, Qilong Zhang, Jingkuan Song
摘要
Defense models against adversarial attacks have grown significantly, but the lack of practical evaluation methods has hindered progress. Evaluation can be defined as looking for defense models' lower bound of robustness given a budget number of iterations and a test dataset. A practical evaluation method should be convenient (i.e., parameter-free), efficient (i.e., fewer iterations) and reliable (i.e., approaching the lower bound of robustness). Towards this target, we propose a parameter-free Adaptive Auto Attack (A <sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">3</sup> ) evaluation method which addresses the efficiency and reliability in a test-time-training fashion. Specifically, by observing that adversarial examples to a specific defense model follow some regularities in their starting points, we design an Adaptive Direction Initialization strategy to speed up the evaluation. Furthermore, to approach the lower bound of robustness under the budget number of iterations, we propose an online statistics-based discarding strategy that automatically identifies and abandons hard-to-attack images. Extensive experiments on nearly 50 widely-used defense models demonstrate the effectiveness of our A <sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">3</sup> . By consuming much fewer iterations than existing methods, i.e., 1/10 on average (10× speed up), we achieve lower robust accuracy in all cases. Notably, we won first place out of 1681 teams in CVPR 2021 White-box Adversarial Attacks on Defense Models competitions with this method. Code is available at: https://github.com/liuye6666/adaptive_auto_attack
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- Natural Color Fool: Towards Boosting Black-box Unrestricted AttacksShengming Yuan, Qilong Zhang, Lianli Gao, Yaya Cheng 等NeurIPS 2022 · 被引用 86 次
- Beyond ImageNet Attack: Towards Crafting Adversarial Examples for Black-box DomainsQilong Zhang, Xiaodan Li, Yuefeng Chen, Jingkuan Song 等ICLR 2022 · 被引用 85 次
- Boosting Adversarial Transferability via Gradient Relevance AttackHegui Zhu, Yuchen Ren, Xiaoyan Sui, Lianping Yang 等ICCV 2023 · 被引用 80 次
- Rethinking Conditional Diffusion Sampling with Progressive GuidanceAnh-Dung Dinh, Daochang Liu, Chang XuNeurIPS 2023 · 被引用 19 次
- MORA: Improving Ensemble Robustness Evaluation with Model Reweighing AttackYunrui Yu, Xitong Gao, Cheng-Zhong XuNeurIPS 2022 · 被引用 14 次
它引用的顶会 Paper22
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 被引用 1,026 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
相关 Paper
- Efficient Robustness Evaluation via Constraint RelaxationChao Pan, Yu Wu, Ke Tang, Qing Li 等AAAI 2025 · 被引用 5 次
- Automated Discovery of Adaptive Attacks on Adversarial DefensesChengyuan Yao, Pavol Bielik, Petar Tsankov, Martin T. VechevNeurIPS 2021 · 被引用 30 次
- Reliable Robustness Evaluation via Automatically Constructed Attack EnsemblesShengcai Liu, Fu Peng, Ke TangAAAI 2023 · 被引用 14 次
- Fast and Reliable Evaluation of Adversarial Robustness with Minimum-Margin AttackRuize Gao, Jiongxiao Wang, Kaiwen Zhou, Feng Liu 等ICML 2022 · 被引用 22 次
- Embracing Adaptation: An Effective Dynamic Defense Strategy Against Adversarial ExamplesShenglin Yin, Kelu Yao, Zhen Xiao, Jieyi LongACM MM 2024
