{"url":"/task/adversarial-attack","name":"Adversarial Attack","slug":"adversarial-attack","description_markdown":"An **Adversarial Attack** is a technique to find a perturbation that changes the prediction of a machine learning model. The perturbation can be very small and imperceptible to human eyes.\n\n\n<span class=\"description-source\">Source: [Recurrent Attention Model with Log-Polar Mapping is Robust against Adversarial Attacks ](https://arxiv.org/abs/2002.05388)</span>","categories":[{"name":"Adversarial","url":"/area/adversarial"},{"name":"Computer Vision","url":"/area/computer-vision"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":1808,"papers_with_code":745,"benchmarks":3,"benchmark_tables_in_archive":3,"benchmark_tables_shown":3,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":11,"subtasks":4,"parent_tasks":0},"benchmarks":[{"leaderboard":"/sota/adversarial-attack-on-cifar-10","slug":"adversarial-attack-on-cifar-10","dataset":"CIFAR-10","dataset_url":"/dataset/cifar-10","rows_in_archive":6,"metrics":["Attack: PGD20","Attack: AutoAttack","Attack: DeepFool","Robust Accuracy"],"first_row_in_archive_order":{"model":"Xu et al.","paper_title":"An Orthogonal Classifier for Improving the Adversarial Robustness of Neural Networks","paper_url":"/paper/an-orthogonal-classifier-for-improving-the","paper_date":"2021-05-19","arxiv_id":"2105.09109","code_links":[{"title":"MTandHJ/roboc","url":"https://github.com/MTandHJ/roboc"}],"syntology":{"n":7,"n_ran":0,"n_unverified":7,"n_pointer_only":0}}},{"leaderboard":"/sota/adversarial-attack-on-cifar-100","slug":"adversarial-attack-on-cifar-100","dataset":"CIFAR-100","dataset_url":"/dataset/cifar-100","rows_in_archive":2,"metrics":["Attack: AutoAttack"],"first_row_in_archive_order":{"model":"3-ensemble of multi-resolution self-ensembles","paper_title":"Ensemble everything everywhere: Multi-scale aggregation for adversarial robustness","paper_url":"/paper/ensemble-everything-everywhere-multi-scale","paper_date":"2024-08-08","arxiv_id":"2408.05446","code_links":[{"title":"stanislavfort/ensemble-everything-everywhere","url":"https://github.com/stanislavfort/ensemble-everything-everywhere"},{"title":"ETH-DISCO/self-ensembling","url":"https://github.com/ETH-DISCO/self-ensembling"}],"syntology":{"n":3,"n_ran":2,"n_unverified":1,"n_pointer_only":3}}},{"leaderboard":"/sota/adversarial-attack-on-wsj0-2mix","slug":"adversarial-attack-on-wsj0-2mix","dataset":"WSJ0-2mix","dataset_url":"/dataset/wsj0-2mix-1","rows_in_archive":1,"metrics":["SDR"],"first_row_in_archive_order":{"model":"ConvTasnet and Dual Path Transformers","paper_title":"Harmonicity Plays a Critical Role in DNN Based Versus in Biologically-Inspired Monaural Speech Segregation Systems","paper_url":"/paper/harmonicity-plays-a-critical-role-in-dnn","paper_date":"2022-03-08","arxiv_id":"2203.04420","code_links":[],"syntology":null}}],"datasets":[{"url":"/dataset/cifar-10","name":"CIFAR-10","full_name":"CIFAR-10","num_papers_in_archive":16145},{"url":"/dataset/cifar-100","name":"CIFAR-100","full_name":"","num_papers_in_archive":9045},{"url":"/dataset/wsj0-2mix-1","name":"WSJ0-2mix","full_name":"","num_papers_in_archive":159},{"url":"/dataset/imagenet-p","name":"ImageNet-P","full_name":"","num_papers_in_archive":32},{"url":"/dataset/nas-bench-1shot1","name":"NAS-Bench-1Shot1","full_name":"","num_papers_in_archive":24},{"url":"/dataset/comma-2k19","name":"comma 2k19","full_name":"","num_papers_in_archive":11},{"url":"/dataset/tcab","name":"TCAB","full_name":"Text Classification Attack Benchmark","num_papers_in_archive":3},{"url":"/dataset/advsuffixes","name":"AdvSuffixes","full_name":"Adversarial Suffixes","num_papers_in_archive":1},{"url":"/dataset/cifar10mnist","name":"Cifar10Mnist","full_name":"","num_papers_in_archive":1},{"url":"/dataset/pointcleannet","name":"PointDenoisingBenchmark","full_name":"","num_papers_in_archive":1},{"url":"/dataset/reap","name":"REAP","full_name":"","num_papers_in_archive":1}],"subtasks":[{"url":"/task/adversarial-attack-detection","name":"Adversarial Attack Detection"},{"url":"/task/adversarial-text","name":"Adversarial Text"},{"url":"/task/backdoor-attack","name":"Backdoor Attack"},{"url":"/task/real-world-adversarial-attack","name":"Real-World Adversarial Attack"}],"parent_tasks":[],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":745,"tagged_in_all":1808,"items":[{"url":"/paper/towards-deep-learning-models-resistant-to","title":"Towards Deep Learning Models Resistant to Adversarial Attacks","date":"2017-06-19","arxiv_id":"1706.06083","repositories_listed":59,"syntology":{"n":17,"n_ran":9,"n_unverified":8,"n_pointer_only":13}},{"url":"/paper/towards-evaluating-the-robustness-of-neural","title":"Towards Evaluating the Robustness of Neural Networks","date":"2016-08-16","arxiv_id":"1608.04644","repositories_listed":27,"syntology":{"n":13,"n_ran":3,"n_unverified":10,"n_pointer_only":1}},{"url":"/paper/universal-and-transferable-adversarial","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","date":"2023-07-27","arxiv_id":"2307.15043","repositories_listed":25,"syntology":{"n":61,"n_ran":33,"n_unverified":28,"n_pointer_only":4}},{"url":"/paper/technical-report-on-the-cleverhans-v210","title":"Technical Report on the CleverHans v2.1.0 Adversarial Examples Library","date":"2016-10-03","arxiv_id":"1610.00768","repositories_listed":13,"syntology":{"n":26,"n_ran":3,"n_unverified":23,"n_pointer_only":26}},{"url":"/paper/the-limitations-of-deep-learning-in","title":"The Limitations of Deep Learning in Adversarial Settings","date":"2015-11-24","arxiv_id":"1511.07528","repositories_listed":11,"syntology":null},{"url":"/paper/score-camimproved-visual-explanations-via","title":"Score-CAM: Score-Weighted Visual Explanations for Convolutional Neural Networks","date":"2019-10-03","arxiv_id":"1910.01279","repositories_listed":9,"syntology":{"n":13,"n_ran":3,"n_unverified":10,"n_pointer_only":2}},{"url":"/paper/theoretically-principled-trade-off-between","title":"Theoretically Principled Trade-off between Robustness and Accuracy","date":"2019-01-24","arxiv_id":"1901.08573","repositories_listed":9,"syntology":{"n":15,"n_ran":12,"n_unverified":3,"n_pointer_only":4}},{"url":"/paper/deep-variational-information-bottleneck","title":"Deep Variational Information Bottleneck","date":"2016-12-01","arxiv_id":"1612.00410","repositories_listed":9,"syntology":{"n":11,"n_ran":6,"n_unverified":5,"n_pointer_only":3}},{"url":"/paper/provable-defenses-against-adversarial","title":"Provable defenses against adversarial examples via the convex outer adversarial polytope","date":"2017-11-02","arxiv_id":"1711.00851","repositories_listed":8,"syntology":{"n":44,"n_ran":21,"n_unverified":23,"n_pointer_only":2}},{"url":"/paper/boosting-adversarial-attacks-with-momentum","title":"Boosting Adversarial Attacks with Momentum","date":"2017-10-17","arxiv_id":"1710.06081","repositories_listed":7,"syntology":{"n":2,"n_ran":1,"n_unverified":1,"n_pointer_only":0}},{"url":"/paper/foolbox-a-python-toolbox-to-benchmark-the","title":"Foolbox: A Python toolbox to benchmark the robustness of machine learning models","date":"2017-07-13","arxiv_id":"1707.04131","repositories_listed":7,"syntology":null},{"url":"/paper/beta-crown-efficient-bound-propagation-with","title":"Beta-CROWN: Efficient Bound Propagation with Per-neuron Split Constraints for Complete and Incomplete Neural Network Robustness Verification","date":"2021-03-11","arxiv_id":"2103.06624","repositories_listed":6,"syntology":{"n":5,"n_ran":4,"n_unverified":1,"n_pointer_only":1}},{"url":"/paper/adversarial-training-for-free","title":"Adversarial Training for Free!","date":"2019-04-29","arxiv_id":"1904.12843","repositories_listed":6,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":1}},{"url":"/paper/ead-elastic-net-attacks-to-deep-neural","title":"EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples","date":"2017-09-13","arxiv_id":"1709.04114","repositories_listed":6,"syntology":{"n":1,"n_ran":0,"n_unverified":1,"n_pointer_only":1}},{"url":"/paper/trasw-tracklet-switch-adversarial-attacks","title":"Tracklet-Switch Adversarial Attack against Pedestrian Multi-Object Tracking Trackers","date":"2021-11-17","arxiv_id":"2111.08954","repositories_listed":5,"syntology":null},{"url":"/paper/disrupting-deepfakes-adversarial-attacks","title":"Disrupting Deepfakes: Adversarial Attacks Against Conditional Image Translation Networks and Facial Manipulation Systems","date":"2020-03-03","arxiv_id":"2003.01279","repositories_listed":5,"syntology":null},{"url":"/paper/real-world-attack-on-mtcnn-face-detection","title":"Real-world adversarial attack on MTCNN face detection system","date":"2019-10-14","arxiv_id":"1910.06261","repositories_listed":5,"syntology":null},{"url":"/paper/enresnet-resnet-ensemble-via-the-feynman-kac","title":"ResNets Ensemble via the Feynman-Kac Formalism to Improve Natural and Robust Accuracies","date":"2018-11-26","arxiv_id":"1811.10745","repositories_listed":5,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":1}},{"url":"/paper/local-gradients-smoothing-defense-against","title":"Local Gradients Smoothing: Defense against localized adversarial attacks","date":"2018-07-03","arxiv_id":"1807.01216","repositories_listed":5,"syntology":null},{"url":"/paper/zoo-zeroth-order-optimization-based-black-box","title":"ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models","date":"2017-08-14","arxiv_id":"1708.03999","repositories_listed":5,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/understanding-the-vulnerability-of-skeleton","title":"Understanding the Vulnerability of Skeleton-based Human Activity Recognition via Black-box Attack","date":"2022-11-21","arxiv_id":"2211.11312","repositories_listed":4,"syntology":null},{"url":"/paper/patch-wise-attack-for-fooling-deep-neural","title":"Patch-wise Attack for Fooling Deep Neural Network","date":"2020-07-14","arxiv_id":"2007.06765","repositories_listed":4,"syntology":null},{"url":"/paper/bert-attack-adversarial-attack-against-bert","title":"BERT-ATTACK: Adversarial Attack Against BERT Using BERT","date":"2020-04-21","arxiv_id":"2004.09984","repositories_listed":4,"syntology":{"n":4,"n_ran":2,"n_unverified":2,"n_pointer_only":1}},{"url":"/paper/advhat-real-world-adversarial-attack-on","title":"AdvHat: Real-world adversarial attack on ArcFace Face ID system","date":"2019-08-23","arxiv_id":"1908.08705","repositories_listed":4,"syntology":{"n":5,"n_ran":4,"n_unverified":1,"n_pointer_only":3}},{"url":"/paper/on-evaluating-adversarial-robustness","title":"On Evaluating Adversarial Robustness","date":"2019-02-18","arxiv_id":"1902.06705","repositories_listed":4,"syntology":null},{"url":"/paper/distributionally-adversarial-attack","title":"Distributionally Adversarial Attack","date":"2018-08-16","arxiv_id":"1808.05537","repositories_listed":4,"syntology":null},{"url":"/paper/learn-to-pay-attention","title":"Learn To Pay Attention","date":"2018-04-06","arxiv_id":"1804.02391","repositories_listed":4,"syntology":null},{"url":"/paper/obfuscated-gradients-give-a-false-sense-of","title":"Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples","date":"2018-02-01","arxiv_id":"1802.00420","repositories_listed":4,"syntology":null},{"url":"/paper/certified-defenses-against-adversarial","title":"Certified Defenses against Adversarial Examples","date":"2018-01-29","arxiv_id":"1801.09344","repositories_listed":4,"syntology":null},{"url":"/paper/boosting-the-transferability-of-adversarial-2","title":"Boosting the Transferability of Adversarial Attacks with Reverse Adversarial Perturbation","date":"2022-10-12","arxiv_id":"2210.05968","repositories_listed":3,"syntology":{"n":6,"n_ran":3,"n_unverified":3,"n_pointer_only":4}}],"syntology_records":17,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}