paper-with-me

홈 › Papers

How many dimensions are required to find an adversarial example?

2023-03-24 · Charles Godfrey, Henry Kvinge, Elise Bishoff, Myles Mckay, Davis Brown, Tim Doster, Eleanor Byler

Past work exploring adversarial vulnerability have focused on situations where an adversary can perturb all dimensions of model input. On the other hand, a range of recent works consider the case where either (i) an adversary can perturb a limited number of input parameters or (ii) a subset of modalities in a multimodal problem. In both of these cases, adversarial examples are effectively constrained to a subspace $V$ in the ambient input space $\mathcal{X}$. Motivated by this, in this work we investigate how adversarial vulnerability depends on $\dim(V)$. In particular, we show that the adversarial success of standard PGD attacks with $\ell^p$ norm constraints behaves like a monotonically increasing function of $\epsilon (\frac{\dim(V)}{\dim \mathcal{X}})^{\frac{1}{q}}$ where $\epsilon$ is the perturbation budget and $\frac{1}{p} + \frac{1}{q} =1$, provided $p > 1$ (the case $p=1$ presents additional subtleties which we analyze in some detail). This functional form can be easily derived from a simple toy linear model, and as such our results land further credence to arguments that adversarial examples are endemic to locally linear models on high dimensional spaces.

📄 PDF Abstract BibTeX arXiv:2303.14173

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Convergence and Margin of Adversarial Training on Separable Data

2019-05-22 · Zachary Charles, Shashank Rajput, Stephen Wright, Dimitris Papailiopoulos

Adversarial training is a technique for training robust machine learning models. To encourage robustness, it iteratively computes adversarial examples for the model, and then re-trains on these examples via some update r…

Are Labels Required for Improving Adversarial Robustness?

2019-05-31 · NeurIPS 2019 12 · Jonathan Uesato, Jean-Baptiste Alayrac, Po-Sen Huang, Robert Stanforth 외

Recent work has uncovered the interesting (and somewhat surprising) finding that training models to be invariant to adversarial perturbations requires substantially larger datasets than those required for standard classi…

4kAdversarial Robustness

Adversarially Robust Learning with Unknown Perturbation Sets

2021-02-03 · Omar Montasser, Steve Hanneke, Nathan Srebro

We study the problem of learning predictors that are robust to adversarial examples with respect to an unknown perturbation set, relying instead on interaction with an adversarial attacker or access to attack oracles, ex…

Copy and Paste: A Simple But Effective Initialization Method for Black-Box Adversarial Attacks

2019-06-14 · Thomas Brunner, Frederik Diehl, Alois Knoll

Many optimization methods for generating black-box adversarial examples have been proposed, but the aspect of initializing said optimizers has not been considered in much detail. We show that the choice of starting point…

valid

Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks

2017-04-04 · Network and Distributed System Security Symposium 2018 2 · Weilin Xu, David Evans, Yanjun Qi

Although deep neural networks (DNNs) have achieved great success in many tasks, they can often be fooled by \emph{adversarial examples} that are generated by adding small but purposeful distortions to natural examples. P…