For discrete perturbation sets between the hypercube and the odd integer grid, the focused width overestimates the detectability radius by at least a √(log n) factor in the Gaussian model and by n^{1/4} for Laplace data.
Detecting adversarial attacks on random samples
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
This paper studies the problem of detecting adversarial perturbations in a sequence of observations. Given a data sample $X_1, \ldots, X_n$ drawn from a standard normal distribution, an adversary, after observing the sample, can perturb each observation by a fixed magnitude or leave it unchanged. We explore the relationship between the perturbation magnitude, the sparsity of the perturbation, and the detectability of the adversary's actions, establishing precise thresholds for when detection becomes impossible.
fields
math.ST 1years
2026 1verdicts
ACCEPT 1representative citing papers
citing papers explorer
-
Focused Width in Adversarial Fake Detection: A Separation
For discrete perturbation sets between the hypercube and the odd integer grid, the focused width overestimates the detectability radius by at least a √(log n) factor in the Gaussian model and by n^{1/4} for Laplace data.