Switch language한국어
Back to the list

Transfer of adversarial robustness between perturbation types

TL;DR AI

Key summary

2 min read
  1. Researchers tested 32 attacks across five perturbation types on adversarially trained ImageNet-subset models.

  2. Robustness proved to be perturbation-specific: defense against one attack type often did not carry over to others.

  3. In some cases, training for one perturbation type even reduced robustness to another.

  4. The study suggests model evaluations and defenses should cover more than the usual L-infinity and L2 settings.

Read the original