vix.ing · top · new · best · stats · spec

Scaling up the randomized gradient-free adversarial attack reveals\n overestimation of robustness using established attacks

2019/03/27 by Francesco Croce, Croce, Francesco, Jonas Rauber +3 · 1 citation
Computer Science · Materials Science · #Adversarial Robustness in Machine Learning #Machine Learning in Materials Science #Advanced Neural Network Applications

paper · pdf · doi:10.48550/arxiv.1903.11359

Abstract

Modern neural networks are highly non-robust against adversarial\nmanipulation. A significant amount of work has been invested in techniques to\ncompute lower bounds on robustness through formal guarantees and to build\nprovably robust models. However, it is still difficult to get guarantees for\nlarger networks or robustness against larger perturbations. Thus attack\nstrategies are needed to provide tight upper bounds on the actual robustness.\nWe significantly improve the randomized gradient-free attack for ReLU networks\n[9], in particular by scaling it up to large networks. We show that our attack\nachieves similar or significantly smaller robust accuracy than state-of-the-art\nattacks like PGD or the one of Carlini and Wagner, thus revealing an\noverestimation of the robustness by these state-of-the-art methods. Our attack\nis not based on a gradient descent scheme and in this sense gradient-free,\nwhich makes it less sensitive to the choice of hyperparameters as no careful\nselection of the stepsize is required.\n

Cited by

Related