Papers › A principled approach for generating adversarial images under non-smooth dissimilarity metrics

A principled approach for generating adversarial images under non-smooth dissimilarity metrics

5 Aug 2019arXiv:1908.01667archive 2025-07-28

Aram-Alexandre Pooladian, Chris Finlay, Tim Hoheisel, Adam Oberman

Deep neural networks perform well on real world data but are prone to adversarial perturbations: small changes in the input easily lead to misclassification. In this work, we propose an attack methodology not only for cases where the perturbations are measured by ℓₚ norms, but in fact any adversarial dissimilarity metric with a closed proximal form. This includes, but is not limited to, ℓ₁, ℓ₂, and ℓ_∞ perturbations; the ℓ₀ counting "norm" (i.e. true sparseness); and the total variation seminorm, which is a (non-ℓₚ) convolutional dissimilarity measuring local pixel changes. Our approach is a natural extension of a recent adversarial attack method, and eliminates the differentiability requirement of the metric. We demonstrate our algorithm, ProxLogBarrier, on the MNIST, CIFAR10, and ImageNet-1k datasets. We consider undefended and defended models, and show that our algorithm easily transfers to various datasets. We observe that ProxLogBarrier outperforms a host of modern adversarial attacks specialized for the ℓ₀ case. Moreover, by altering images in the total variation seminorm, we shed light on a new class of perturbations that exploit neighboring pixel information.

PaperPDFCode

Code

APooladian/ProxLogBarrierAttack officialmentioned in papermentioned on GitHubpytorch report
cfinlay/logbarrier mentioned on GitHubpytorch report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

Adversarial Attack

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections