arrow
Return

HO-FMN: Hyperparameter optimization for fast minimum-norm attacks

delete2025-02-01
delete0
delete
OA
AI
R
Raffaele Mura
G
Giuseppe Floris
L
Luca Scionis
G
Giorgio Piras
M
Maura Pintor *
A
Ambra Demontis
G
Giorgio Giacinto
B
Battista Biggio
F
Fabio Roli
DOI:10.1016/j.neucom.2024.128918delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Gradient-based attacks area primary tool to evaluate robustness of machine-learning models. However, many attacks tend to provide overly-optimistic evaluations as they use fixed loss functions, optimizers, step-size schedulers, and default hyperparameters. In this work, we tackle these limitations by proposing a parametric variation of the well-known fast minimum-norm attack algorithm, whose loss, optimizer, step-size scheduler, and hyperparameters can be dynamically adjusted. We re-evaluate 12 robust models, showing that our attack finds smaller adversarial perturbations without requiring any additional tuning. This also enables reporting adversarial robustness as a function of the perturbation budget, providing amore complete evaluation than that offered by fixed-budget attacks, while remaining efficient. We release our open-source code at https: //github.com/pralab/HO-FMN.
Keywords:
Machine learning security
Adversarial examples
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Neurocomputing cover
Neurocomputing
IF:
6.5
Papers:
2.5W
Citations:
6.5W

Organization

U
university of cagliari
Scholars:
1.2W
Papers: 9.7K
Citations: 9