A classic PGD attack with a dynamic step-size schedule and an adaptive early stop attains 100% success with l2 distance 0.89 and l_infinity=1/255 on ImageNet classifiers, outperforming specialized imperceptible attacks.
Towards deep learning models resistant to adversarial attacks,
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
citation-role summary
background 1
citation-polarity summary
fields
cs.LG 1years
2024 1verdicts
CONDITIONAL 1roles
background 1polarities
unclear 1representative citing papers
citing papers explorer
-
PGD-Imp: Rethinking and Unleashing Potential of Classic PGD with Dual Strategies for Imperceptible Adversarial Attacks
A classic PGD attack with a dynamic step-size schedule and an adaptive early stop attains 100% success with l2 distance 0.89 and l_infinity=1/255 on ImageNet classifiers, outperforming specialized imperceptible attacks.