Lune

ICML2021顶会

Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image Classifiers

Francesco Croce, Matthias Hein

2021年份
68被引次数
27顶会引用

摘要

We show that when taking into account also the image domain [0,1]d[0,1]^d, established l1l_1-projected gradient descent (PGD) attacks are suboptimal as they do not consider that the effective threat model is the intersection of the l1l_1-ball and [0,1]d[0,1]^d. We study the expected sparsity of the steepest descent step for this effective threat model and show that the exact projection onto this set is computationally feasible and yields better performance. Moreover, we propose an adaptive form of PGD which is highly effective even with a small budget of iterations. Our resulting l1l_1-APGD is a strong white-box attack showing that prior works overestimated their l1l_1-robustness. Using l1l_1-APGD for adversarial training we get a robust classifier with SOTA l1l_1-robustness. Finally, we combine l1l_1-APGD and an adaptation of the Square Attack to l1l_1 into l1l_1-AutoAttack, an ensemble of attacks which reliably assesses adversarial robustness for the threat model of l1l_1-ball intersected with [0,1]d[0,1]^d.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper27

问问它们各自怎么用它

它引用的顶会 Paper11

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖