paper-with-me

Papers

Taking Care of The Discretization Problem: A Comprehensive Study of the Discretization Problem and A Black-Box Adversarial Attack in Discrete Integer Domain

2019-05-19 · Lei Bu, Yuchao Duan, Fu Song, Zhe Zhao

Numerous methods for crafting adversarial examples were proposed recently with high success rate. Since most existing machine learning based classifiers normalize images into some continuous, real vector, domain firstly, attacks often craft adversarial examples in such domain. However, "adversarial" examples may become benign after denormalizing them back into the discrete integer domain, known as the discretization problem. This problem was mentioned in some work, but has received relatively little attention. In this work, we first conduct a comprehensive study of existing methods and tools for crafting. We theoretically analyze 34 representative methods and empirically study 20 representative open source tools for crafting adversarial images. Our study reveals that the discretization problem is far more serious than originally thought. This suggests that the discretization problem should be taken into account seriously when crafting adversarial examples and measuring attack success rate. As a first step towards addressing this problem in black-box scenario, we propose a black-box method which reduces the adversarial example searching problem to a derivative-free optimization problem. Our method is able to craft adversarial images by derivative-free search in the discrete integer domain. Experimental results show that our method is comparable to recent white-box methods (e.g., FGSM, BIM and C\&W) and achieves significantly higher success rate in terms of adversarial examples in the discrete integer domain than recent black-box methods (e.g., ZOO, NES-PGD and Bandits). Moreover, our method is able to handle models that is non-differentiable and successfully break the winner of NIPS 2017 competition on defense with 95\% success rate. Our results suggest that discrete optimization algorithms open up a promising area of research into effective black-box attacks.

📄 PDF Abstract BibTeX arXiv:1905.07672

Code (1)

persistz/derivative-free-attack

Tasks

Adversarial Attack

Similar Papers 제목 키워드 기반

Career Incentives, Risk-Taking, and Sorting Dynamics: Evidence from Top Financial Advisers

2025-03-31 · Jun Honda

We examine how career concerns influence the behavior and mobility of financial advisers. Drawing on a uniquely comprehensive matched panel that combines employer-employee data with a longstanding national ranking, our s…

Optimal conditions for connectedness of discretized sets

2018-08-09 · Boris Brimkov, Valentin E. Brimkov

Constructing a discretization of a given set is a major problem in various theoretical and applied disciplines. An offset discretization of a set $X$ is obtained by taking the integer points inside a closed neighborhood …

Adaptive Discretization for Consistency Models

2025-10-20 · Jiayu Bai, Zhanbo Feng, Zhijie Deng, Tianqi Hou 외 arxiv

Consistency Models (CMs) have shown promise for efficient one-step generation. However, most existing CMs rely on manually designed discretization schemes, which can cause repeated adjustments for different noise schedul…

Talking Turns: Benchmarking Audio Foundation Models on Turn-Taking Dynamics

2025-03-03 · Siddhant Arora, Zhiyun Lu, Chung-Cheng Chiu, Ruoming Pang 외

The recent wave of audio foundation models (FMs) could provide new capabilities for conversational modeling. However, there have been limited efforts to evaluate these audio FMs comprehensively on their ability to have n…

BenchmarkingSpoken Dialogue Systems

Discretization-independent multifidelity operator learning for partial differential equations

2025-07-09 · Jacob Hauck, Yanzhi Zhang arxiv

We develop a new and general encode-approximate-reconstruct operator learning model that leverages learned neural representations of bases for input and output function distributions. We introduce the concepts of \textit…

Computational Efficiency