Megadose Built for builders and researchers.

Pareto-Improving Adversarial Attacks with Primal-Dual Regularization

· ArXiv · AI/CL/LG ·
The paper argues the apparent trade-off between attack strength and stealth comes from fixed-budget testing, not the attacks themselves.

The authors introduce ST, a primal-dual wrapper meant to make transferable adversarial attacks less perceptible without lowering success rates. It adds an L-infinity saturation regularizer and solves it with a two-step update, without extra models or perceptual priors. In their tests at epsilon 16/255, ST improves imperceptibility by 17% on LPIPS and 14% on NIQE on average while preserving or improving ASR. ArXiv · AI/CL/LG's note.

score 4

Categories: Research