Carla Seatzu

HO-FMN: Hyperparameter optimization for fast minimum-norm attacks

Mura, Raffaele
Co-primo
;
Floris, Giuseppe
Co-primo
;
Scionis, Luca
Co-primo
;
Piras, Giorgio;Pintor, Maura
;
Demontis, Ambra;Giacinto, Giorgio;Biggio, Battista
Penultimo
;
Roli, Fabio
Ultimo
2025-01-01

Abstract

Gradient-based attacks are a primary tool to evaluate robustness of machine-learning models. However, many attacks tend to provide overly-optimistic evaluations as they use fixed loss functions, optimizers, step-size schedulers, and default hyperparameters. In this work, we tackle these limitations by proposing a parametric variation of the well-known fast minimum-norm attack algorithm, whose loss, optimizer, step-size scheduler, and hyperparameters can be dynamically adjusted. We re-evaluate 12 robust models, showing that our attack finds smaller adversarial perturbations without requiring any additional tuning. This also enables reporting adversarial robustness as a function of the perturbation budget, providing a more complete evaluation than that offered by fixed-budget attacks, while remaining efficient. We release our open-source code at https://github.com/pralab/HO-FMN.
2025
2024
Inglese
616
128918
1
10
10
Esperti anonimi
scientifica
Machine learning security; Adversarial examples
no
Mura, Raffaele; Floris, Giuseppe; Scionis, Luca; Piras, Giorgio; Pintor, Maura; Demontis, Ambra; Giacinto, Giorgio; Biggio, Battista; Roli, Fabio ...espandi
1.1 Articolo in rivista
info:eu-repo/semantics/article
1 Contributo su Rivista::1.1 Articolo in rivista
262
9
open
   Cybersecurity for AI-Augmented Systems
   Sec4AI4Sec
   European Commission
   Horizon Europe Framework Programme
   101120393
File in questo prodotto:
File Dimensione Formato  
1-s2.0-S0925231224016898-main.pdf

accesso aperto

Descrizione: open access
Tipologia: versione editoriale (VoR)
Dimensione 2.61 MB
Formato Adobe PDF
2.61 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Questionario e social

Condividi su:
Impostazioni cookie