Pith. sign in

REVIEW 2 cited by

Adversarial Examples in Constrained Domains

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2011.01183 v3 pith:LFYR47CK submitted 2020-11-02 cs.CR cs.LG

classification cs.CRcs.LG
keywords domainsadversarialconstrainedexamplesunconstrainedadversaryalgorithmsconstraints
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Machine learning algorithms have been shown to be vulnerable to adversarial manipulation through systematic modification of inputs (e.g., adversarial examples) in domains such as image recognition. Under the default threat model, the adversary exploits the unconstrained nature of images; each feature (pixel) is fully under control of the adversary. However, it is not clear how these attacks translate to constrained domains that limit which and how features can be modified by the adversary (e.g., network intrusion detection). In this paper, we explore whether constrained domains are less vulnerable than unconstrained domains to adversarial example generation algorithms. We create an algorithm for generating adversarial sketches: targeted universal perturbation vectors which encode feature saliency within the envelope of domain constraints. To assess how these algorithms perform, we evaluate them in constrained (e.g., network intrusion detection) and unconstrained (e.g., image recognition) domains. The results demonstrate that our approaches generate misclassification rates in constrained domains that were comparable to those of unconstrained domains (greater than 95%). Our investigation shows that the narrow attack surface exposed by constrained domains is still sufficiently large to craft successful adversarial examples; and thus, constraints do not appear to make a domain robust. Indeed, with as little as five randomly selected features, one can still generate adversarial examples.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Insights on Adversarial Attacks for Tabular Machine Learning via a Systematic Literature Review

    cs.LG 2025-06 conditional novelty 5.0 of 10

    A systematic review of 53 papers on adversarial attacks for tabular machine learning finds the field fragmented, with efficacy over-emphasized and transferability, plausibility, and semantic preservation under-addressed.

  2. Constrained Network Adversarial Attacks: Validity, Robustness, and Transferability

    cs.CR 2025-05 reject novelty 4.0 of 10

    On NSL-KDD, between 19.7% and 76.2% of adversarial examples from common attacks violate the paper's network constraints, and filtering them to feasible inputs sharply lowers measured attack severity on several classifiers.

Pith tools