Guided Adversarial Attack for Evaluating and Enhancing Adversarial Defenses

Advances in the development of adversarial attacks have been fundamental to\nthe progress of adversarial defense research. Efficient and effective attacks\nare crucial for reliable evaluation of defenses, and also for developing robust\nmodels. Adversarial attacks are often generated by maximizing standard losses\nsuch as the cross-entropy loss or maximum-margin loss within a constraint set\nusing Projected Gradient Descent (PGD). In this work, we introduce a relaxation\nterm to the standard loss, that finds more suitable gradient-directions,\nincreases attack efficacy and leads to more efficient adversarial training. We\npropose Guided Adversarial Margin Attack (GAMA), which utilizes function\nmapping of the clean image to guide the generation of adversaries, thereby\nresulting in stronger attacks. We evaluate our attack against multiple defenses\nand show improved performance when compared to existing attacks. Further, we\npropose Guided Adversarial Training (GAT), which achieves state-of-the-art\nperformance amongst single-step defenses by utilizing the proposed relaxation\nterm for both attack generation and training.\n

Paper

References (43)

Scroll for more · 31 remaining

Similar papers

© 2026 NYSGPT2525 LLC