Pith. sign in

Adversarial Risk and the Dangers of Evaluating Against Weak Attacks

2 Pith papers cite this work. Polarity classification is still indexing.

2 Pith papers citing it
abstract

This paper investigates recently proposed approaches for defending against adversarial examples and evaluating adversarial robustness. We motivate 'adversarial risk' as an objective for achieving models robust to worst-case inputs. We then frame commonly used attacks and evaluation metrics as defining a tractable surrogate objective to the true adversarial risk. This suggests that models may optimize this surrogate rather than the true adversarial risk. We formalize this notion as 'obscurity to an adversary,' and develop tools and heuristics for identifying obscured models and designing transparent models. We demonstrate that this is a significant problem in practice by repurposing gradient-free optimization techniques into adversarial attacks, which we use to decrease the accuracy of several recently proposed defenses to near zero. Our hope is that our formulations and results will help researchers to develop more powerful defenses.

fields

cs.CR 2

years

2026 1 2019 1

verdicts

UNVERDICTED 2

representative citing papers

Stateful Detection of Black-Box Adversarial Attacks

cs.CR · 2019-07-12 · unverdicted · novelty 7.0

The paper argues for stateful defenses over stateless ones to detect adversarial example generation via query history and introduces query blinding as a counter-attack.

citing papers explorer

Showing 2 of 2 citing papers.

  • Stateful Detection of Black-Box Adversarial Attacks cs.CR · 2019-07-12 · unverdicted · none · ref 39 · internal anchor

    The paper argues for stateful defenses over stateless ones to detect adversarial example generation via query history and introduces query blinding as a counter-attack.

  • NeuroTrace: Inference Provenance-Based Detection of Adversarial Examples cs.CR · 2026-04-15 · unverdicted · none · ref 15

    NeuroTrace framework builds heterogeneous graphs of inference provenance to detect adversarial examples in DNNs, showing strong transferable performance across attack families in vision and malware domains.