$L_0$ Attacks are adversarial attacks that modify the fewest number of input features (pixels) — constrained by $|x - x_{adv}|_0 leq k$, changing at most $k$ features but potentially by a large amount, creating sparse, localized perturbations.
Key $L_0$ Attack Methods
- JSMA: Jacobian-based Saliency Map Attack — greedily selects the most impactful pixels to modify.
- SparseFool: Extends DeepFool to the $L_0$ setting — finds sparse perturbations from geometric reasoning.
- One-Pixel Attack: Extreme $L_0$ attack — modifies just one pixel using differential evolution.
- Sparse PGD: Adapts PGD to the $L_0$ ball using top-$k$ projection.
Why It Matters
- Physical Attacks: $L_0$ attacks model real-world adversarial patches or stickers (few localized changes).
- Interpretable: Changes to a few pixels are easy to visualize and understand.
- Sensor Tampering: In industrial settings, $L_0$ models individual sensor failure or targeted tampering.
$L_0$ Attacks are the precision strike — modifying just a few carefully chosen features to fool the model with minimal, localized changes.
l0 attacksl0ai safety
Explore 500+ Semiconductor & AI Topics
From EUV lithography to CUDA optimization — search the full knowledge base or chat with our AI assistant.