$L_infty$ Attacks are adversarial attacks that perturb every input feature by at most $epsilon$ — constrained within a hypercube $|x - x_{adv}|_infty leq epsilon$, making small, imperceptible changes to all features simultaneously.
Key $L_infty$ Attack Methods
- FGSM: Single-step sign of gradient: $x_{adv} = x + epsilon cdot ext{sign}(\nabla_x L)$.
- PGD: Multi-step projected gradient descent with random start — the standard strong attack.
- AutoAttack: Ensemble of parameter-free attacks (APGD-CE, APGD-DLR, FAB, Square) — the benchmark standard.
- C&W $L_infty$: Lagrangian relaxation of the constraint for minimum $epsilon$ finding.
Why It Matters
- Standard Threat Model: $L_infty$ is the most common threat model in adversarial robustness research.
- Imperceptibility: Small per-pixel changes are the least visible to human inspectors.
- Practical: Models sensor drift in industrial settings where all readings shift slightly.
$L_infty$ Attacks are the subtle, everywhere perturbation — small, uniform changes across all features that are the standard threat model in adversarial ML.
l-infinity attacksai safety
Related Topics
Explore 500+ Semiconductor & AI Topics
From EUV lithography to CUDA optimization — search the full knowledge base or chat with our AI assistant.