l-infinity attacks

**$L_infty$ Attacks** are **adversarial attacks that perturb every input feature by at most $epsilon$** — constrained within a hypercube $|x - x_{adv}|_infty leq epsilon$, making small, imperceptible changes to all features simultaneously. **Key $L_infty$ Attack Methods** - **FGSM**: Single-step sign of gradient: $x_{adv} = x + epsilon cdot ext{sign}( abla_x L)$. - **PGD**: Multi-step projected gradient descent with random start — the standard strong attack. - **AutoAttack**: Ensemble of parameter-free attacks (APGD-CE, APGD-DLR, FAB, Square) — the benchmark standard. - **C&W $L_infty$**: Lagrangian relaxation of the constraint for minimum $epsilon$ finding. **Why It Matters** - **Standard Threat Model**: $L_infty$ is the most common threat model in adversarial robustness research. - **Imperceptibility**: Small per-pixel changes are the least visible to human inspectors. - **Practical**: Models sensor drift in industrial settings where all readings shift slightly. **$L_infty$ Attacks** are **the subtle, everywhere perturbation** — small, uniform changes across all features that are the standard threat model in adversarial ML.

Go deeper with CFSGPT

Get AI-powered deep-dives, save terms, and run advanced simulations — free account.

Create Free Account