Scaling up the Randomized Gradient-Free Adversarial Attack Reveals Overestimation of Robustness Using Established Attacks

被引:12
作者
Croce, Francesco [1 ]
Rauber, Jonas [1 ]
Hein, Matthias [1 ]
机构
[1] Univ Tubingen, Dept Comp Sci, Tubingen, Germany
关键词
Adversarial attacks; Adversarial robustness; White-box attacks; Gradient-free attacks;
D O I
10.1007/s11263-019-01213-0
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Modern neural networks are highly non-robust against adversarial manipulation. A significant amount of work has been invested in techniques to compute lower bounds on robustness through formal guarantees and to build provably robust models. However, it is still difficult to get guarantees for larger networks or robustness against larger perturbations. Thus attack strategies are needed to provide tight upper bounds on the actual robustness. We significantly improve the randomized gradient-free attack for ReLU networks (Croce and Hein in GCPR, 2018), in particular by scaling it up to large networks. We show that our attack achieves similar or significantly smaller robust accuracy than state-of-the-art attacks like PGD or the one of Carlini and Wagner, thus revealing an overestimation of the robustness by these state-of-the-art methods. Our attack is not based on a gradient descent scheme and in this sense gradient-free, which makes it less sensitive to the choice of hyperparameters as no careful selection of the stepsize is required.
引用
收藏
页码:1028 / 1046
页数:19
相关论文
共 38 条
[1]  
[Anonymous], 2014, The cifar-10
[2]  
Arora Raman, 2018, ICLR
[3]  
Athalye A, 2018, PR MACH LEARN RES, V80
[4]   A Fast Iterative Shrinkage-Thresholding Algorithm for Linear Inverse Problems [J].
Beck, Amir ;
Teboulle, Marc .
SIAM JOURNAL ON IMAGING SCIENCES, 2009, 2 (01) :183-202
[5]  
Brendel W., 2018, P INT C LEARN REPR
[6]  
Carlini N., 2017, P AISEC, P3
[7]   Towards Evaluating the Robustness of Neural Networks [J].
Carlini, Nicholas ;
Wagner, David .
2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, :39-57
[8]   A First-Order Primal-Dual Algorithm for Convex Problems with Applications to Imaging [J].
Chambolle, Antonin ;
Pock, Thomas .
JOURNAL OF MATHEMATICAL IMAGING AND VISION, 2011, 40 (01) :120-145
[9]  
CROCE F, 2018, GCPR
[10]  
Croce F, 2019, PR MACH LEARN RES, V89