Pith. sign in

REVIEW 1 cited by

On the Efficacy of Metrics to Describe Adversarial Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2301.13028 v1 pith:W4VJZ7M3 submitted 2023-01-30 cs.LG

classification cs.LG
keywords adversarialmetricsattacksimagedefensesobserveattackcapability
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Adversarial defenses are naturally evaluated on their ability to tolerate adversarial attacks. To test defenses, diverse adversarial attacks are crafted, that are usually described in terms of their evading capability and the L0, L1, L2, and Linf norms. We question if the evading capability and L-norms are the most effective information to claim that defenses have been tested against a representative attack set. To this extent, we select image quality metrics from the state of the art and search correlations between image perturbation and detectability. We observe that computing L-norms alone is rarely the preferable solution. We observe a strong correlation between the identified metrics computed on an adversarial image and the output of a detector on such an image, to the extent that they can predict the response of a detector with approximately 0.94 accuracy. Further, we observe that metrics can classify attacks based on similar perturbations and similar detectability. This suggests a possible review of the approach to evaluate detectors, where additional metrics are included to assure that a representative attack dataset is selected.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Distortion-Aware Adversarial Attacks on Bounding Boxes of Object Detectors

    cs.CV 2024-12 conditional novelty 4.0 of 10

    An iterative gradient-based attack, guided by predicted bounding-box masks and controlled by a normalized cross-correlation distortion threshold, causes object detectors to misdetect objects with high reported success.

Pith tools