{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/the-logbarrier-adversarial-attack-making","title":"The LogBarrier adversarial attack: making effective use of decision boundary information","arxiv_id":"1903.10396","date":"2019-03-25","proceeding":"ICCV 2019 10","authors":["Chris Finlay","Aram-Alexandre Pooladian","Adam M. Oberman"],"abstract":"Adversarial attacks for image classification are small perturbations to\nimages that are designed to cause misclassification by a model. Adversarial\nattacks formally correspond to an optimization problem: find a minimum norm\nimage perturbation, constrained to cause misclassification. A number of\neffective attacks have been developed. However, to date, no gradient-based\nattacks have used best practices from the optimization literature to solve this\nconstrained minimization problem. We design a new untargeted attack, based on\nthese best practices, using the established logarithmic barrier method. On\naverage, our attack distance is similar or better than all state-of-the-art\nattacks on benchmark datasets (MNIST, CIFAR10, ImageNet-1K). In addition, our\nmethod performs significantly better on the most challenging images, those\nwhich normally require larger perturbations for misclassification. We employ\nthe LogBarrier attack on several adversarially defended models, and show that\nit adversarially perturbs all images more efficiently than other attacks: the\ndistance needed to perturb all images is significantly smaller with the\nLogBarrier attack than with other state-of-the-art attacks.","url_abs":"http://arxiv.org/abs/1903.10396v1","url_pdf":"http://arxiv.org/pdf/1903.10396v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"the-logbarrier-adversarial-attack-making","repo_url":"https://github.com/cfinlay/logbarrier","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"image-classification","task_name":"Image Classification"},{"task_slug":"image-classification","task_name":"image-classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}