Mind the box: -APGD for sparse adversarial attacks on image classifiers
arXiv:2103.01208
Abstract
We show that when taking into account also the image domain , established -projected gradient descent (PGD) attacks are suboptimal as they do not consider that the effective threat model is the intersection of the -ball and . We study the expected sparsity of the steepest descent step for this effective threat model and show that the exact projection onto this set is computationally feasible and yields better performance. Moreover, we propose an adaptive form of PGD which is highly effective even with a small budget of iterations. Our resulting -APGD is a strong white-box attack showing that prior works overestimated their -robustness. Using -APGD for adversarial training we get a robust classifier with SOTA -robustness. Finally, we combine -APGD and an adaptation of the Square Attack to into -AutoAttack, an ensemble of attacks which reliably assesses adversarial robustness for the threat model of -ball intersected with .
In ICML 2021. Fixed typos in Eq. (3) and Eq. (4)
References in corpus (7)
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
- Fast is better than free: Revisiting adversarial training
- Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples
- RobustBench: a standardized adversarial robustness benchmark
- Adversarial Robustness Against the Union of Multiple Perturbation Models
- Do Wider Neural Networks Really Help Adversarial Robustness?
- Towards Defending Multiple -norm Bounded Adversarial Perturbations via Gated Batch Normalization