Browse State-of-the-Art › Adversarial Attack
Adversarial Attack
745 papers with code · 3 benchmarks · 11 datasets archive 2025-07-28
An Adversarial Attack is a technique to find a perturbation that changes the prediction of a machine learning model. The perturbation can be very small and imperceptible to human eyes.
Source: Recurrent Attention Model with Log-Polar Mapping is Robust against Adversarial Attacks
Description from the archive archive 2025-07-28.
Benchmarks archive 2025-07-28
3 leaderboard tables shown for this task, 3 with rows (a “benchmark” on this site is a table with at least one row, as on /sota), ordered by row count. “Best model” is the first row in the archive's own order at snapshot; nothing is re-ranked here and metric direction is not recorded in the archive. PwC's Trend sparklines are not in the archive, so that column is omitted.
| Dataset | Best model (first row in archive order) | Paper | Code | Syntology | Compare |
|---|---|---|---|---|---|
| CIFAR-10 (6 rows) | Xu et al. | An Orthogonal Classifier for Improving the Adversarial Robustness... | code | Syntology ran 0 of 7 samples · 7 unverified | Compare |
| CIFAR-100 (2 rows) | 3-ensemble of multi-resolution self-ensembles | Ensemble everything everywhere: Multi-scale aggregation for... | code | Syntology ran 2 of 3 samples · 1 unverified | Compare |
| WSJ0-2mix (1 row) | ConvTasnet and Dual Path Transformers | Harmonicity Plays a Critical Role in DNN Based Versus in... | — | — | Compare |
Syntology column: samples harvested from the paper's repositories and executed on synthesized fixtures; “ran” is not a correctness claim and does not order the table. A dash means no Syntology record for that paper, not a recorded non-run. Read from the graph 2026-09-24.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
11 datasets whose archive record lists this task, ordered by the archive's paper count.
Subtasks archive 2025-07-28
4 subtasks in the archive's task tree.
Most implemented papers archive 2025-07-28
30 shown of 745 papers with code (1,808 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
19 Jun 2017 59 repositories listed Syntology ran 9 of 17 samples · 8 unverified · 13 pointer-only (licence)Its principled nature also enables us to identify methods for both training and attacking neural networks that are reliable and, in a certain sense, universal.
-
16 Aug 2016 27 repositories listed Syntology ran 3 of 13 samples · 10 unverified · 1 pointer-only (licence)Defensive distillation is a recently proposed approach that can take an arbitrary neural network, and increase its robustness, reducing the success rate of current attacks' ability to find adversarial examples from 95%…
-
27 Jul 2023 25 repositories listed Syntology ran 33 of 61 samples · 28 unverified · 4 pointer-only (licence)Specifically, our approach finds a suffix that, when attached to a wide range of queries for an LLM to produce objectionable content, aims to maximize the probability that the model produces an affirmative response…
-
3 Oct 2016 13 repositories listed Syntology ran 3 of 26 samples · 23 unverified · 26 pointer-only (licence)An adversarial example library for constructing attacks, building defenses, and benchmarking both
-
24 Nov 2015 11 repositories listedIn this work, we formalize the space of adversaries against deep neural networks (DNNs) and introduce a novel class of algorithms to craft adversarial samples based on a precise understanding of the mapping between…
-
3 Oct 2019 9 repositories listed Syntology ran 3 of 13 samples · 10 unverified · 2 pointer-only (licence)Recently, increasing attention has been drawn to the internal mechanisms of convolutional neural networks, and the reason why the network makes specific decisions.
-
24 Jan 2019 9 repositories listed Syntology ran 12 of 15 samples · 3 unverified · 4 pointer-only (licence)We identify a trade-off between robustness and accuracy that serves as a guiding principle in the design of defenses against adversarial examples.
-
1 Dec 2016 9 repositories listed Syntology ran 6 of 11 samples · 5 unverified · 3 pointer-only (licence)We present a variational approximation to the information bottleneck of Tishby et al.
-
2 Nov 2017 8 repositories listed Syntology ran 21 of 44 samples · 23 unverified · 2 pointer-only (licence)We propose a method to learn deep ReLU-based classifiers that are provably robust against norm-bounded adversarial perturbations on the training data.
-
17 Oct 2017 7 repositories listed Syntology ran 1 of 2 samples · 1 unverifiedTo further improve the success rates for black-box attacks, we apply momentum iterative algorithms to an ensemble of models, and show that the adversarially trained models with a strong defense ability are also…
-
13 Jul 2017 7 repositories listedFoolbox is a new Python package to generate such adversarial perturbations and to quantify and compare the robustness of machine learning models.
-
11 Mar 2021 6 repositories listed Syntology ran 4 of 5 samples · 1 unverified · 1 pointer-only (licence)Compared to the typically tightest but very costly semidefinite programming (SDP) based incomplete verifiers, we obtain higher verified accuracy with three orders of magnitudes less verification time.
-
29 Apr 2019 6 repositories listed Syntology ran 1 of 1 samples · 0 unverified · 1 pointer-only (licence)Adversarial training, in which a network is trained on adversarial examples, is one of the few defenses against adversarial attacks that withstands strong attacks.
-
13 Sep 2017 6 repositories listed Syntology ran 0 of 1 samples · 1 unverified · 1 pointer-only (licence)Recent studies have highlighted the vulnerability of deep neural networks (DNNs) to adversarial examples - a visually indistinguishable adversarial image can easily be crafted to cause a well-trained model to…
-
17 Nov 2021 5 repositories listedMulti-Object Tracking (MOT) has achieved aggressive progress and derived many excellent deep learning trackers.
-
3 Mar 2020 5 repositories listedThis type of manipulated images and video have been coined Deepfakes.
-
14 Oct 2019 5 repositories listedRecent studies proved that deep learning approaches achieve remarkable results on face detection task.
-
26 Nov 2018 5 repositories listed Syntology ran 1 of 1 samples · 0 unverified · 1 pointer-only (licence)However, both natural and robust accuracies, in classifying clean and adversarial images, respectively, of the trained robust models are far from satisfactory.
-
3 Jul 2018 5 repositories listedDeep neural networks (DNNs) have shown vulnerability to adversarial attacks, i.
-
14 Aug 2017 5 repositories listed Syntology ran 1 of 1 samples · 0 unverifiedHowever, different from leveraging attack transferability from substitute models, we propose zeroth order optimization (ZOO) based attacks to directly estimate the gradients of the targeted DNN for generating…
-
21 Nov 2022 4 repositories listedVia BASAR, we find on-manifold adversarial samples are extremely deceitful and rather common in skeletal motions, in contrast to the common belief that adversarial samples only exist off-manifold.
-
14 Jul 2020 4 repositories listedBy adding human-imperceptible noise to clean images, the resultant adversarial examples can fool other unknown models.
-
21 Apr 2020 4 repositories listed Syntology ran 2 of 4 samples · 2 unverified · 1 pointer-only (licence)Adversarial attacks for discrete data (such as texts) have been proved significantly more challenging than continuous data (such as images) since it is difficult to generate adversarial samples with gradient-based…
-
23 Aug 2019 4 repositories listed Syntology ran 4 of 5 samples · 1 unverified · 3 pointer-only (licence)In this paper we propose a novel easily reproducible technique to attack the best public Face ID system ArcFace in different shooting conditions.
-
18 Feb 2019 4 repositories listedCorrectly evaluating defenses against adversarial examples has proven to be extremely difficult.
-
16 Aug 2018 4 repositories listedRecent work on adversarial attack has shown that Projected Gradient Descent (PGD) Adversary is a universal first-order adversary, and the classifier adversarially trained by PGD is robust against a wide range of…
-
6 Apr 2018 4 repositories listedWe propose an end-to-end-trainable attention module for convolutional neural network (CNN) architectures built for image classification.
-
1 Feb 2018 4 repositories listedWe identify obfuscated gradients, a kind of gradient masking, as a phenomenon that leads to a false sense of security in defenses against adversarial examples.
-
29 Jan 2018 4 repositories listedWhile neural networks have achieved high accuracy on standard image classification benchmarks, their accuracy drops to nearly zero in the presence of small adversarial perturbations to test inputs.
-
12 Oct 2022 3 repositories listed Syntology ran 3 of 6 samples · 3 unverified · 4 pointer-only (licence)Furthermore, RAP can be naturally combined with many existing black-box attack techniques, to further boost the transferability.
Syntology lines on 17 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections