l2 attacks

**$L_2$ Attacks** are **adversarial attacks that constrain the total Euclidean magnitude of the perturbation** — $|x - x_{adv}|_2 leq epsilon$, allowing larger changes in a few features while keeping the overall perturbation small in the geometric (Euclidean) sense. **Key $L_2$ Attack Methods** - **C&W $L_2$**: Carlini & Wagner — the strongest $L_2$ attack, using Adam optimization with change-of-variables and margin-based objectives. - **DeepFool**: Finds the minimum $L_2$ perturbation to cross the decision boundary — iterative linearization. - **PGD-$L_2$**: Projected gradient descent with $L_2$ ball projection. - **DDN**: Decoupled direction and norm — separates perturbation direction from magnitude optimization. **Why It Matters** - **Natural Metric**: $L_2$ distance is the natural geometric distance between images/signals. - **Different From $L_infty$**: $L_2$ robustness does not imply $L_infty$ robustness (and vice versa). - **Randomized Smoothing**: $L_2$ is the natural norm for randomized smoothing certified defenses. **$L_2$ Attacks** are **the geometric perturbation** — finding adversarial examples that are close in Euclidean distance to the original input.

Go deeper with CFSGPT

Get AI-powered deep-dives, save terms, and run advanced simulations — free account.

Create Free Account