Deep Neural Networks (DNNs) have demonstrated remarkable success in various domains but remain susceptible to adversarial examples: slightly altered inputs designed to induce misclassification. While adversarial attacks typically optimize under \(L_p\) -norm constraints, attacks based on the \(L_0\) -norm, which prioritize input sparsity, are less studied due to their complex, non-convex nature. These sparse adversarial examples challenge existing defenses by altering a minimal subset of features, potentially uncovering more subtle DNN weaknesses. However, the current \(L_0\) -norm attack methodologies face a trade-off between accuracy and efficiency—either precise but computationally intense or expedient but imprecise. This paper proposes a novel, scalable, and effective approach to generate adversarial examples of the \(L_0\) norm, aimed at refining the robustness evaluation of DNNs against such perturbations.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Evaluating Model Robustness Using Adaptive Sparse L0 Regularization

  • Weiyou Liu,
  • Zhengyang Li,
  • Weitong Chen

摘要

Deep Neural Networks (DNNs) have demonstrated remarkable success in various domains but remain susceptible to adversarial examples: slightly altered inputs designed to induce misclassification. While adversarial attacks typically optimize under \(L_p\) -norm constraints, attacks based on the \(L_0\) -norm, which prioritize input sparsity, are less studied due to their complex, non-convex nature. These sparse adversarial examples challenge existing defenses by altering a minimal subset of features, potentially uncovering more subtle DNN weaknesses. However, the current \(L_0\) -norm attack methodologies face a trade-off between accuracy and efficiency—either precise but computationally intense or expedient but imprecise. This paper proposes a novel, scalable, and effective approach to generate adversarial examples of the \(L_0\) norm, aimed at refining the robustness evaluation of DNNs against such perturbations.