2019

Testing Robustness Against Unforeseen Adversaries

Kaufmann, Max, Kang, Daniel, Sun, Yi et al.

Understand

Adversarial robustness research primarily focuses on L_p perturbations, and most defenses are developed with identical training-time and test-time adversaries.

  • However, in real-world applications developers are unlikely to have access to the full range of attacks or corruptions their system will face.
  • Furthermore, worst-case inputs are likely to be diverse and need not be constrained to the L_p ball.
  • To narrow in on this discrepancy between research and reality we introduce ImageNet-UA, a framework for evaluating model robustness against a range of unforeseen adversaries, including eighteen new non-L_p attacks.

Reading the bibliography…