Papers › Distributionally Adversarial Attack

Distributionally Adversarial Attack

16 Aug 2018arXiv:1808.05537archive 2025-07-28

Tianhang Zheng, Changyou Chen, Kui Ren

Recent work on adversarial attack has shown that Projected Gradient Descent (PGD) Adversary is a universal first-order adversary, and the classifier adversarially trained by PGD is robust against a wide range of first-order attacks. It is worth noting that the original objective of an attack/defense model relies on a data distribution p(𝐱), typically in the form of risk maximization/minimization, e.g., max/min𝔼ₚ₍₍ₓ₎₎ℒ(𝐱) with p(𝐱) some unknown data distribution and ℒ(·) a loss function. However, since PGD generates attack samples independently for each data sample based on ℒ(·), the procedure does not necessarily lead to good generalization in terms of risk optimization. In this paper, we achieve the goal by proposing distributionally adversarial attack (DAA), a framework to solve an optimal {\em adversarial-data distribution}, a perturbed distribution that satisfies the L_∞ constraint but deviates from the original data distribution to increase the generalization risk maximally. Algorithmically, DAA performs optimization on the space of potential data distributions, which introduces direct dependency between all data points when generating adversarial samples. DAA is evaluated by attacking state-of-the-art defense models, including the adversarially-trained models provided by {\em MIT MadryLab}. Notably, DAA ranks {\em the first place} on MadryLab's white-box leaderboards, reducing the accuracy of their secret MNIST model to 88.79% (with l_∞ perturbations of ϵ= 0.3) and the accuracy of their secret CIFAR model to 44.71% (with l_∞ perturbations of ϵ= 8.0). Code for the experiments is released on \url{https://github.com/tianzheng4/Distributionally-Adversarial-Attack}.

PaperPDFCode

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

Code

tianzheng4/Distributionally-Adversarial-Attack officialmentioned in papermentioned on GitHubtf report
MadryLab/cifar10_challenge officialmentioned in papertfMIT report
MadryLab/mnist_challenge officialmentioned in papertfMIT report
shubhamuttam1/Pytorch-DAA mentioned on GitHubpytorch report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

Adversarial Attack

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections