Transfer of adversarial robustness between perturbation types

TL;DR AI
2 min readKey summary
Researchers tested 32 attacks across five perturbation types on adversarially trained ImageNet-subset models.
Robustness proved to be perturbation-specific: defense against one attack type often did not carry over to others.
In some cases, training for one perturbation type even reduced robustness to another.
The study suggests model evaluations and defenses should cover more than the usual L-infinity and L2 settings.



