Pith. sign in

REVIEW 2 cited by

EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1709.04114 v3 pith:EMMIOH4G submitted 2017-09-13 stat.ML cs.CRcs.LG

classification stat.MLcs.CRcs.LG
keywords adversarialexamplesdnnsattackdistortionelastic-netattackscrafting
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
abstract

Recent studies have highlighted the vulnerability of deep neural networks (DNNs) to adversarial examples - a visually indistinguishable adversarial image can easily be crafted to cause a well-trained model to misclassify. Existing methods for crafting adversarial examples are based on $L_2$ and $L_\infty$ distortion metrics. However, despite the fact that $L_1$ distortion accounts for the total variation and encourages sparsity in the perturbation, little has been developed for crafting $L_1$-based adversarial examples. In this paper, we formulate the process of attacking DNNs via adversarial examples as an elastic-net regularized optimization problem. Our elastic-net attacks to DNNs (EAD) feature $L_1$-oriented adversarial examples and include the state-of-the-art $L_2$ attack as a special case. Experimental results on MNIST, CIFAR10 and ImageNet show that EAD can yield a distinct set of adversarial examples with small $L_1$ distortion and attains similar attack performance to the state-of-the-art methods in different attack scenarios. More importantly, EAD leads to improved attack transferability and complements adversarial training for DNNs, suggesting novel insights on leveraging $L_1$ distortion in adversarial machine learning and security implications of DNNs.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Protecting Neural Networks with Hierarchical Random Switching: Towards Better Robustness-Accuracy Trade-off for Stochastic Defenses

    cs.LG 2019-08 conditional novelty 6.0 of 10

    A stochastic neural network defense using randomly switched parallel weight channels achieves a high defense-per-accuracy-drop ratio on MNIST and CIFAR-10 and is reported as the first defense against adversarial repro...

  2. Binary Iterative Method for Non-targeted Adversarial Attack

    cs.LG 2026-07 reject novelty 2.0 of 10

    Halving the BIM step size each iteration (BinIM) yields stronger non-targeted ImageNet attacks than FGSM/BIM/VAM on three classifiers, with unsupported claims that this finds local minima.

Pith tools