$L_2$ Attacks are adversarial attacks that constrain the total Euclidean magnitude of the perturbation — $|x - x_{adv}|_2 leq epsilon$, allowing larger changes in a few features while keeping the overall perturbation small in the geometric (Euclidean) sense.
Key $L_2$ Attack Methods
- C&W $L_2$: Carlini & Wagner — the strongest $L_2$ attack, using Adam optimization with change-of-variables and margin-based objectives.
- DeepFool: Finds the minimum $L_2$ perturbation to cross the decision boundary — iterative linearization.
- PGD-$L_2$: Projected gradient descent with $L_2$ ball projection.
- DDN: Decoupled direction and norm — separates perturbation direction from magnitude optimization.
Why It Matters
- Natural Metric: $L_2$ distance is the natural geometric distance between images/signals.
- Different From $L_infty$: $L_2$ robustness does not imply $L_infty$ robustness (and vice versa).
- Randomized Smoothing: $L_2$ is the natural norm for randomized smoothing certified defenses.
$L_2$ Attacks are the geometric perturbation — finding adversarial examples that are close in Euclidean distance to the original input.
l2 attacksl2ai safety
Explore 500+ Semiconductor & AI Topics
From EUV lithography to CUDA optimization — search the full knowledge base or chat with our AI assistant.