Pith. sign in

Provably Minimally-Distorted Adversarial Examples

1 Pith paper cite this work. Polarity classification is still indexing.

1 Pith paper citing it
abstract

The ability to deploy neural networks in real-world, safety-critical systems is severely limited by the presence of adversarial examples: slightly perturbed inputs that are misclassified by the network. In recent years, several techniques have been proposed for increasing robustness to adversarial examples --- and yet most of these have been quickly shown to be vulnerable to future attacks. For example, over half of the defenses proposed by papers accepted at ICLR 2018 have already been broken. We propose to address this difficulty through formal verification techniques. We show how to construct provably minimally distorted adversarial examples: given an arbitrary neural network and input sample, we can construct adversarial examples which we prove are of minimal distortion. Using this approach, we demonstrate that one of the recent ICLR defense proposals, adversarial retraining, provably succeeds at increasing the distortion required to construct adversarial examples by a factor of 4.2.

fields

cs.LG 1

years

2025 1

verdicts

CONDITIONAL 1

representative citing papers

Position: Adversarial ML for LLMs Is Not Making Any Progress

cs.LG · 2025-02-04 · conditional · novelty 6.0

The authors argue that LLM-era adversarial machine learning is less well-defined, harder to solve, and harder to evaluate, so meaningful progress may not be achievable or trackable in the current paradigm.

citing papers explorer

Showing 1 of 1 citing paper.

  • Position: Adversarial ML for LLMs Is Not Making Any Progress cs.LG · 2025-02-04 · conditional · none · ref 2017 · internal anchor

    The authors argue that LLM-era adversarial machine learning is less well-defined, harder to solve, and harder to evaluate, so meaningful progress may not be achievable or trackable in the current paradigm.