Pith. sign in

REVIEW 1 cited by

Alternating Objectives Generates Stronger PGD-Based Adversarial Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2212.07992 v1 pith:VQZLPK5D submitted 2022-12-15 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords adversarialattacksobjectivealternatingchoicesdifferentlossobjectives
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Designing powerful adversarial attacks is of paramount importance for the evaluation of $\ell_p$-bounded adversarial defenses. Projected Gradient Descent (PGD) is one of the most effective and conceptually simple algorithms to generate such adversaries. The search space of PGD is dictated by the steepest ascent directions of an objective. Despite the plethora of objective function choices, there is no universally superior option and robustness overestimation may arise from ill-suited objective selection. Driven by this observation, we postulate that the combination of different objectives through a simple loss alternating scheme renders PGD more robust towards design choices. We experimentally verify this assertion on a synthetic-data example and by evaluating our proposed method across 25 different $\ell_{\infty}$-robust models and 3 datasets. The performance improvement is consistent, when compared to the single loss counterparts. In the CIFAR-10 dataset, our strongest adversarial attack outperforms all of the white-box components of AutoAttack (AA) ensemble, as well as the most powerful attacks existing on the literature, achieving state-of-the-art results in the computational budget of our study ($T=100$, no restarts).

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Towards Million-Scale Adversarial Robustness Evaluation With Stronger Individual Attacks

    cs.LG 2024-11 conditional novelty 6.0 of 10

    PMA, a probability-margin loss attack, consistently outperforms existing individual white-box attacks, and a one-million-image evaluation shows much lower robust accuracy than small-scale tests.

Pith tools