Skip to main navigation Skip to search Skip to main content

Assessing Robustness via Score-Based Adversarial Image Generation

  • Marcel Kollovieh
  • , Lukas Gosch
  • , Marten Lienen
  • , Yan Scholten
  • , Leo Schwinn
  • , Stephan Günnemann
  • Technical University of Munich
  • Munich Center for Machine Learning

Research output: Contribution to journalArticlepeer-review

1 Scopus citations

Abstract

Most adversarial attacks and defenses focus on perturbations within small ℓp-norm con-straints. However, ℓp threat models cannot capture all relevant semantics-preserving per-turbations, and hence, the scope of robustness evaluations is limited. In this work, we introduce Score-Based Adversarial Generation (ScoreAG), a novel framework that leverages the advancements in score-based generative models to generate unrestricted adversarial examples that overcome the limitations of ℓp-norm constraints. Unlike traditional methods, ScoreAG maintains the core semantics of images while generating adversarial examples, ei-ther by transforming existing images or synthesizing new ones entirely from scratch. We further exploit the generative capability of ScoreAG to purify images, empirically enhancing the robustness of classifiers. Our extensive empirical evaluation demonstrates that ScoreAG improves upon the majority of state-of-the-art attacks and defenses across multiple bench-marks. This work highlights the importance of investigating adversarial examples bounded by semantics rather than ℓp-norm constraints. ScoreAG represents an important step towards more encompassing robustness assessments.

Original languageEnglish
JournalTransactions on Machine Learning Research
Volume2024
StatePublished - 2024

Fingerprint

Dive into the research topics of 'Assessing Robustness via Score-Based Adversarial Image Generation'. Together they form a unique fingerprint.

Cite this