Papers › Multi-attacks: Many images + the same adversarial attack → many target labels

Multi-attacks: Many images + the same adversarial attack → many target labels

4 Aug 2023arXiv:2308.03792archive 2025-07-28

Stanislav Fort

We show that we can easily design a single adversarial perturbation P that changes the class of n images X₁,X₂,…,Xₙ from their original, unperturbed classes c₁, c₂,…,cₙ to desired (not necessarily all the same) classes c^*₁,c^*₂,…,c^*ₙ for up to hundreds of images and target classes at once. We call these \textit{multi-attacks}. Characterizing the maximum n we can achieve under different conditions such as image resolution, we estimate the number of regions of high class confidence around a particular image in the space of pixels to be around 10^(𝒪(100)), posing a significant problem for exhaustive defense strategies. We show several immediate consequences of this: adversarial attacks that change the resulting class based on their intensity, and scale-independent adversarial examples. To demonstrate the redundancy and richness of class decision boundaries in the pixel space, we look for its two-dimensional sections that trace images and spell words using particular classes. We also show that ensembling reduces susceptibility to multi-attacks, and that classifiers trained on random labels are more susceptible. Our code is available on GitHub.

PaperPDFCode

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

Code

stanislavfort/multi-attacks officialmentioned in paperMIT report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

Adversarial Attack

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections