[2003.01690] Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
The field of defense strategies against adversarial attacks has significantly grown over the last years, but progress is hampered as the evaluation of adversarial defenses is often insufficient and thus gives a wrong impression of robustness. Many promising defenses could be broken later on, making it difficult to identify the state-of-the-art. Frequent pitfalls in the evaluation are improper tuning of hyperparameters of the attacks, gradient obfuscation or masking. In this paper we first propose two extensions of the PGD-attack overcoming failures due to suboptimal step size and problems of the objective function. We then combine our novel attacks with two complementary existing ones to form a parameter-free, computationally affordable and user-independent ensemble of attacks to test adversarial robustness. We apply our ensemble to over 50 models from papers published at recent top machine learning and computer vision venues. In all except one of the cases we achieve lower robust test accuracy than reported in these papers, often by more than $10\%$, identifying several broken defenses.
Reliable Evaluation of Adversarial Robustness with an Ensemble of Diverse Parameter-free Attacks Francesco Croce 1 Matthias Hein 1 Abstract variations are using other losses (Zhang et al., 2019b) and boost robustness via generation of…
related reading
- Your Out-of-Distribution Detection Method is Not Robust!arxiv.org
- [1610.00768] Technical Report on the CleverHans v2.1.0 Adversarial Examples Libraryarxiv.org
- Some Lessons from Adversarial Machine Learning | FAR.AIfar.ai
- Solving adversarial attacks in computer vision as a baby version of general AI alignment | Stanislav Fortstanislavfort.com
- Announcing Safety Research Grantsthinkingmachines.ai
- GitHub - SoyGema/pulling_acegithub.com
- 2312.06942arxiv.org
- GitHub - requie/AI-Red-Teaming-Guide: A comprehensive guide to adversarial testing and security evaluation of AI systems, helping organizations identify vulnerabilities before attackers exploit them.github.com
- Adversarial Examples Are Not Bugs, They Are Features – gradient sciencegradientscience.org
- [2602.04899] Phantom Transfer: Data-level Defences are Insufficient Against Data Poisoningarxiv.org
- An SDE Framework for Adversarial Training, with Convergence and Robustness Analysisarxiv.org
- Research Areas in Evaluation and Guarantees in Reinforcement Learning (The Alignment Project by UK AISI) — AI Alignment Forumalignmentforum.org