paper-with-me

Papers

Lattice Climber Attack: Adversarial attacks for randomized mixtures of classifiers

2025-06-12 · Lucas Gnecco-Heredia, Benjamin Negrevergne, Yann Chevaleyre

Finite mixtures of classifiers (a.k.a. randomized ensembles) have been proposed as a way to improve robustness against adversarial attacks. However, existing attacks have been shown to not suit this kind of classifier. In this paper, we discuss the problem of attacking a mixture in a principled way and introduce two desirable properties of attacks based on a geometrical analysis of the problem (effectiveness and maximality). We then show that existing attacks do not meet both of these properties. Finally, we introduce a new attack called {\em lattice climber attack} with theoretical guarantees in the binary linear setting, and demonstrate its performance by conducting experiments on synthetic and real datasets.

📄 PDF Abstract BibTeX arXiv:2506.10888

Code (1)

lucasgneccoh/lattice_climber_attack 공식 구현 pytorch

Similar Papers 제목 키워드 기반

Adversarial attacks for mixtures of classifiers

2023-07-20 · Lucas Gnecco Heredia, Benjamin Negrevergne, Yann Chevaleyre

Mixtures of classifiers (a.k.a. randomized ensembles) have been proposed as a way to improve robustness against adversarial attacks. However, it has been shown that existing attacks are not well suited for this kind of c…

On Certifying Robustness against Backdoor Attacks via Randomized Smoothing

2020-02-26 · Binghui Wang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang Gong

Backdoor attack is a severe security threat to deep neural networks (DNNs). We envision that, like adversarial examples, there will be a cat-and-mouse game for backdoor attacks, i.e., new empirical defenses are developed…

Backdoor Attack

Randomization matters. How to defend against strong adversarial attacks

2020-02-26 · Rafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre 외

Is there a classifier that ensures optimal robustness against all adversarial attacks? This paper answers this question by adopting a game-theoretic point of view. We show that adversarial attacks and defenses form an in…

Randomization matters How to defend against strong adversarial attacks

2020-01-01 · ICML 2020 1 · Rafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre 외

\emph{Is there a classifier that ensures optimal robustness against all adversarial attacks?} This paper answers this question by adopting a game-theoretic point of view. We show that adversarial attacks and defenses for…

Evaluating randomized smoothing as a defense against adversarial attacks in trajectory prediction

2026-03-11 · Julian F. Schumann, Eduardo Figueiredo, Frederik Baymler Mathiesen, Luca Laurenti 외 arxiv

Accurate and robust trajectory prediction is essential for safe and efficient autonomous driving, yet recent work has shown that even state-of-the-art prediction models are highly vulnerable to inputs being mildly pertur…

Trajectory PredictionAutonomous Driving