<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Adversarial machine learning</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Adversarial_machine_learning"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/ext.math.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Adversarial_machine_learning rootpage-Adversarial_machine_learning skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Adversarial machine learning</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">Not to be confused with <a href="Generative_adversarial_network" title="Generative adversarial network">Generative adversarial network</a>.</div>
<style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1246091330">
/* start https://en.wikipedia.org/ */
.mw-parser-output .sidebar{width:22em;float:right;clear:right;margin:0.5em 0 1em 1em;background:var(--background-color-neutral-subtle,#f8f9fa);border:1px solid var(--border-color-base,#a2a9b1);padding:0.2em;text-align:center;line-height:1.4em;font-size:88%;border-collapse:collapse;display:table}body.skin-minerva .mw-parser-output .sidebar{display:table!important;float:right!important;margin:0.5em 0 1em 1em!important}.mw-parser-output .sidebar-subgroup{width:100%;margin:0;border-spacing:0}.mw-parser-output .sidebar-left{float:left;clear:left;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-none{float:none;clear:both;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-outer-title{padding:0 0.4em 0.2em;font-size:125%;line-height:1.2em;font-weight:bold}.mw-parser-output .sidebar-top-image{padding:0.4em}.mw-parser-output .sidebar-top-caption,.mw-parser-output .sidebar-pretitle-with-top-image,.mw-parser-output .sidebar-caption{padding:0.2em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-pretitle{padding:0.4em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-title,.mw-parser-output .sidebar-title-with-pretitle{padding:0.2em 0.8em;font-size:145%;line-height:1.2em}.mw-parser-output .sidebar-title-with-pretitle{padding:0.1em 0.4em}.mw-parser-output .sidebar-image{padding:0.2em 0.4em 0.4em}.mw-parser-output .sidebar-heading{padding:0.1em 0.4em}.mw-parser-output .sidebar-content{padding:0 0.5em 0.4em}.mw-parser-output .sidebar-content-with-subgroup{padding:0.1em 0.4em 0.2em}.mw-parser-output .sidebar-above,.mw-parser-output .sidebar-below{padding:0.3em 0.8em;font-weight:bold}.mw-parser-output .sidebar-collapse .sidebar-above,.mw-parser-output .sidebar-collapse .sidebar-below{border-top:1px solid #aaa;border-bottom:1px solid #aaa}.mw-parser-output .sidebar-navbar{text-align:right;font-size:115%;padding:0 0.4em 0.4em}.mw-parser-output .sidebar-list-title{padding:0 0.4em;text-align:left;font-weight:bold;line-height:1.6em;font-size:105%}.mw-parser-output .sidebar-list-title-c{padding:0 0.4em;text-align:center;margin:0 3.3em}@media(max-width:640px){body.mediawiki .mw-parser-output .sidebar{width:100%!important;clear:both;float:none!important;margin-left:0!important;margin-right:0!important}}body.skin--responsive .mw-parser-output .sidebar a>img{max-width:none!important}@media screen{html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media print{body.ns-0 .mw-parser-output .sidebar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r886047488">
/* start https://en.wikipedia.org/ */
.mw-parser-output .nobold{font-weight:normal}
/* end https://en.wikipedia.org/ */
</style><table class="sidebar sidebar-collapse nomobile nowraplinks"><tbody><tr><td class="sidebar-pretitle">Part of a series on</td></tr><tr><th class="sidebar-title-with-pretitle"><a href="Machine_learning" title="Machine learning">Machine learning</a><br>and <a href="Data_mining" title="Data mining">data mining</a></th></tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)">Paradigms</div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Supervised_learning" title="Supervised learning">Supervised learning</a></li>
<li><a href="Unsupervised_learning" title="Unsupervised learning">Unsupervised learning</a></li>
<li><a href="Semi-supervised_learning" class="mw-redirect" title="Semi-supervised learning">Semi-supervised learning</a></li>
<li><a href="Self-supervised_learning" title="Self-supervised learning">Self-supervised learning</a></li>
<li><a href="Reinforcement_learning" title="Reinforcement learning">Reinforcement learning</a></li>
<li><a href="Meta-learning_(computer_science)" title="Meta-learning (computer science)">Meta-learning</a></li>
<li><a href="Online_machine_learning" title="Online machine learning">Online learning</a></li>
<li><a href="Batch_learning" class="mw-redirect" title="Batch learning">Batch learning</a></li>
<li><a href="Curriculum_learning" title="Curriculum learning">Curriculum learning</a></li>
<li><a href="Rule-based_machine_learning" title="Rule-based machine learning">Rule-based learning</a></li>
<li><a href="Neuro-symbolic_AI" title="Neuro-symbolic AI">Neuro-symbolic AI</a></li>
<li><a href="Neuromorphic_engineering" class="mw-redirect" title="Neuromorphic engineering">Neuromorphic engineering</a></li>
<li><a href="Quantum_machine_learning" title="Quantum machine learning">Quantum machine learning</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)">Problems</div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Statistical_classification" title="Statistical classification">Classification</a></li>
<li><a href="Generative_model" title="Generative model">Generative modeling</a></li>
<li><a href="Regression_analysis" title="Regression analysis">Regression</a></li>
<li><a href="Cluster_analysis" title="Cluster analysis">Clustering</a></li>
<li><a href="Dimensionality_reduction" title="Dimensionality reduction">Dimensionality reduction</a></li>
<li><a href="Density_estimation" title="Density estimation">Density estimation</a></li>
<li><a href="Anomaly_detection" title="Anomaly detection">Anomaly detection</a></li>
<li><a href="Data_cleaning" class="mw-redirect" title="Data cleaning">Data cleaning</a></li>
<li><a href="Automated_machine_learning" title="Automated machine learning">AutoML</a></li>
<li><a href="Association_rule_learning" title="Association rule learning">Association rules</a></li>
<li><a href="Semantic_analysis_(machine_learning)" title="Semantic analysis (machine learning)">Semantic analysis</a></li>
<li><a href="Structured_prediction" title="Structured prediction">Structured prediction</a></li>
<li><a href="Feature_engineering" title="Feature engineering">Feature engineering</a></li>
<li><a href="Feature_learning" title="Feature learning">Feature learning</a></li>
<li><a href="Learning_to_rank" title="Learning to rank">Learning to rank</a></li>
<li><a href="Grammar_induction" title="Grammar induction">Grammar induction</a></li>
<li><a href="Ontology_learning" title="Ontology learning">Ontology learning</a></li>
<li><a href="Multimodal_learning" title="Multimodal learning">Multimodal learning</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)"><div style="display: inline-block; line-height: 1.2em; padding: .1em 0;"><a href="Supervised_learning" title="Supervised learning">Supervised learning</a><br><span class="nobold"><span style="font-size: 85%;">(<b><a href="Statistical_classification" title="Statistical classification">classification</a></b> • <b><a href="Regression_analysis" title="Regression analysis">regression</a></b>)</span></span> </div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Apprenticeship_learning" title="Apprenticeship learning">Apprenticeship learning</a></li>
<li><a href="Decision_tree_learning" title="Decision tree learning">Decision trees</a></li>
<li><a href="Ensemble_learning" title="Ensemble learning">Ensembles</a>
<ul><li><a href="Bootstrap_aggregating" title="Bootstrap aggregating">Bagging</a></li>
<li><a href="Boosting_(machine_learning)" title="Boosting (machine learning)">Boosting</a></li>
<li><a href="Random_forest" title="Random forest">Random forest</a></li></ul></li>
<li><a href="K-nearest_neighbors_algorithm" title="K-nearest neighbors algorithm"><i>k</i>-NN</a></li>
<li><a href="Linear_regression" title="Linear regression">Linear regression</a></li>
<li><a href="Naive_Bayes_classifier" title="Naive Bayes classifier">Naive Bayes</a></li>
<li><a href="Artificial_neural_network" class="mw-redirect" title="Artificial neural network">Artificial neural networks</a></li>
<li><a href="Logistic_regression" title="Logistic regression">Logistic regression</a></li>
<li><a href="Perceptron" title="Perceptron">Perceptron</a></li>
<li><a href="Relevance_vector_machine" title="Relevance vector machine">Relevance vector machine (RVM)</a></li>
<li><a href="Support_vector_machine" title="Support vector machine">Support vector machine (SVM)</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)"><a href="Cluster_analysis" title="Cluster analysis">Clustering</a></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="BIRCH" title="BIRCH">BIRCH</a></li>
<li><a href="CURE_algorithm" title="CURE algorithm">CURE</a></li>
<li><a href="Hierarchical_clustering" title="Hierarchical clustering">Hierarchical</a></li>
<li><a href="K-means_clustering" title="K-means clustering"><i>k</i>-means</a></li>
<li><a href="Fuzzy_clustering" title="Fuzzy clustering">Fuzzy</a></li>
<li><a href="Expectation%E2%80%93maximization_algorithm" title="Expectation–maximization algorithm">Expectation–maximization (EM)</a></li>
<li><br><a href="DBSCAN" title="DBSCAN">DBSCAN</a></li>
<li><a href="OPTICS_algorithm" title="OPTICS algorithm">OPTICS</a></li>
<li><a href="Mean_shift" title="Mean shift">Mean shift</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)"><a href="Dimensionality_reduction" title="Dimensionality reduction">Dimensionality reduction</a></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Factor_analysis" title="Factor analysis">Factor analysis</a></li>
<li><a href="Canonical_correlation" title="Canonical correlation">CCA</a></li>
<li><a href="Independent_component_analysis" title="Independent component analysis">ICA</a></li>
<li><a href="Linear_discriminant_analysis" title="Linear discriminant analysis">LDA</a></li>
<li><a href="Non-negative_matrix_factorization" title="Non-negative matrix factorization">NMF</a></li>
<li><a href="Principal_component_analysis" title="Principal component analysis">PCA</a></li>
<li><a href="Proper_generalized_decomposition" title="Proper generalized decomposition">PGD</a></li>
<li><a href="T-distributed_stochastic_neighbor_embedding" title="T-distributed stochastic neighbor embedding">t-SNE</a></li>
<li><a href="Sparse_dictionary_learning" title="Sparse dictionary learning">SDL</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)"><a href="Structured_prediction" title="Structured prediction">Structured prediction</a></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Graphical_model" title="Graphical model">Graphical models</a>
<ul><li><a href="Bayesian_network" title="Bayesian network">Bayes net</a></li>
<li><a href="Conditional_random_field" title="Conditional random field">Conditional random field</a></li>
<li><a href="Hidden_Markov_model" title="Hidden Markov model">Hidden Markov</a></li></ul></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)"><a href="Anomaly_detection" title="Anomaly detection">Anomaly detection</a></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Random_sample_consensus" title="Random sample consensus">RANSAC</a></li>
<li><a href="K-nearest_neighbors_algorithm" title="K-nearest neighbors algorithm"><i>k</i>-NN</a></li>
<li><a href="Local_outlier_factor" title="Local outlier factor">Local outlier factor</a></li>
<li><a href="Isolation_forest" title="Isolation forest">Isolation forest</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)"><a href="Neural_network_(machine_learning)" title="Neural network (machine learning)">Neural networks</a></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Autoencoder" title="Autoencoder">Autoencoder</a></li>
<li><a href="Deep_learning" title="Deep learning">Deep learning</a></li>
<li><a href="Feedforward_neural_network" title="Feedforward neural network">Feedforward neural network</a></li>
<li><a href="Recurrent_neural_network" title="Recurrent neural network">Recurrent neural network</a>
<ul><li><a href="Long_short-term_memory" title="Long short-term memory">LSTM</a></li>
<li><a href="Gated_recurrent_unit" title="Gated recurrent unit">GRU</a></li>
<li><a href="Echo_state_network" title="Echo state network">ESN</a></li>
<li><a href="Reservoir_computing" title="Reservoir computing">reservoir computing</a></li></ul></li>
<li><a href="Boltzmann_machine" title="Boltzmann machine">Boltzmann machine</a>
<ul><li><a href="Restricted_Boltzmann_machine" title="Restricted Boltzmann machine">Restricted</a></li></ul></li>
<li><a href="Generative_adversarial_network" title="Generative adversarial network">GAN</a></li>
<li><a href="Diffusion_model" title="Diffusion model">Diffusion model</a></li>
<li><a href="Self-organizing_map" title="Self-organizing map">SOM</a></li>
<li><a href="Convolutional_neural_network" title="Convolutional neural network">Convolutional neural network</a>
<ul><li><a href="U-Net" title="U-Net">U-Net</a></li>
<li><a href="LeNet" title="LeNet">LeNet</a></li>
<li><a href="AlexNet" title="AlexNet">AlexNet</a></li>
<li><a href="DeepDream" title="DeepDream">DeepDream</a></li></ul></li>
<li><a href="Neural_field" title="Neural field">Neural field</a>
<ul><li><a href="Neural_radiance_field" title="Neural radiance field">Neural radiance field</a></li>
<li><a href="Physics-informed_neural_networks" title="Physics-informed neural networks">Physics-informed neural networks</a></li></ul></li>
<li><a href="Transformer_(deep_learning_architecture)" title="Transformer (deep learning architecture)">Transformer</a>
<ul><li><a href="Vision_transformer" title="Vision transformer">Vision</a></li></ul></li>
<li><a href="Mamba_(deep_learning_architecture)" title="Mamba (deep learning architecture)">Mamba</a></li>
<li><a href="Spiking_neural_network" title="Spiking neural network">Spiking neural network</a></li>
<li><a href="Memtransistor" title="Memtransistor">Memtransistor</a></li>
<li><a href="Electrochemical_RAM" title="Electrochemical RAM">Electrochemical RAM</a> (ECRAM)</li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)"><a href="Reinforcement_learning" title="Reinforcement learning">Reinforcement learning</a></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Q-learning" title="Q-learning">Q-learning</a></li>
<li><a href="Policy_gradient_method" title="Policy gradient method">Policy gradient</a></li>
<li><a href="State%E2%80%93action%E2%80%93reward%E2%80%93state%E2%80%93action" title="State–action–reward–state–action">SARSA</a></li>
<li><a href="Temporal_difference_learning" title="Temporal difference learning">Temporal difference (TD)</a></li>
<li><a href="Multi-agent_reinforcement_learning" title="Multi-agent reinforcement learning">Multi-agent</a>
<ul><li><a href="Self-play_(reinforcement_learning_technique)" class="mw-redirect" title="Self-play (reinforcement learning technique)">Self-play</a></li></ul></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)">Learning with humans</div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Active_learning_(machine_learning)" title="Active learning (machine learning)">Active learning</a></li>
<li><a href="Crowdsourcing" title="Crowdsourcing">Crowdsourcing</a></li>
<li><a href="Human-in-the-loop" title="Human-in-the-loop">Human-in-the-loop</a></li>
<li><a href="Mechanistic_interpretability" title="Mechanistic interpretability">Mechanistic interpretability</a></li>
<li><a href="Reinforcement_learning_from_human_feedback" title="Reinforcement learning from human feedback">RLHF</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)">Model diagnostics</div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Coefficient_of_determination" title="Coefficient of determination">Coefficient of determination</a></li>
<li><a href="Confusion_matrix" title="Confusion matrix">Confusion matrix</a></li>
<li><a href="Learning_curve_(machine_learning)" title="Learning curve (machine learning)">Learning curve</a></li>
<li><a href="Receiver_operating_characteristic" title="Receiver operating characteristic">ROC curve</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)">Mathematical foundations</div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Kernel_machines" class="mw-redirect" title="Kernel machines">Kernel machines</a></li>
<li><a href="Bias%E2%80%93variance_tradeoff" title="Bias–variance tradeoff">Bias–variance tradeoff</a></li>
<li><a href="Computational_learning_theory" title="Computational learning theory">Computational learning theory</a></li>
<li><a href="Empirical_risk_minimization" title="Empirical risk minimization">Empirical risk minimization</a></li>
<li><a href="Occam_learning" title="Occam learning">Occam learning</a></li>
<li><a href="Probably_approximately_correct_learning" title="Probably approximately correct learning">PAC learning</a></li>
<li><a href="Statistical_learning_theory" title="Statistical learning theory">Statistical learning</a></li>
<li><a href="Vapnik%E2%80%93Chervonenkis_theory" title="Vapnik–Chervonenkis theory">VC theory</a></li>
<li><a href="Topological_deep_learning" title="Topological deep learning">Topological deep learning</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)">Journals and conferences</div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="AAAI_Conference_on_Artificial_Intelligence" title="AAAI Conference on Artificial Intelligence">AAAI</a></li>
<li><a href="ECML_PKDD" title="ECML PKDD">ECML PKDD</a></li>
<li><a href="Conference_on_Neural_Information_Processing_Systems" title="Conference on Neural Information Processing Systems">NeurIPS</a></li>
<li><a href="International_Conference_on_Machine_Learning" title="International Conference on Machine Learning">ICML</a></li>
<li><a href="International_Conference_on_Learning_Representations" title="International Conference on Learning Representations">ICLR</a></li>
<li><a href="International_Joint_Conference_on_Artificial_Intelligence" title="International Joint Conference on Artificial Intelligence">IJCAI</a></li>
<li><a href="Machine_Learning_(journal)" title="Machine Learning (journal)">ML</a></li>
<li><a href="Journal_of_Machine_Learning_Research" title="Journal of Machine Learning Research">JMLR</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed machine-learning-list-title"><div class="sidebar-list-title" style="border-top:1px solid #aaa; text-align:center;;color: var(--color-base)">Related articles</div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Glossary_of_artificial_intelligence" title="Glossary of artificial intelligence">Glossary of artificial intelligence</a></li>
<li><a href="List_of_datasets_for_machine-learning_research" title="List of datasets for machine-learning research">List of datasets for machine-learning research</a>
<ul><li><a href="List_of_datasets_in_computer_vision_and_image_processing" title="List of datasets in computer vision and image processing">List of datasets in computer vision and image processing</a></li></ul></li>
<li><a href="Outline_of_machine_learning" title="Outline of machine learning">Outline of machine learning</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-navbar"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></td></tr></tbody></table>
<p><b>Adversarial machine learning</b> is the study of the attacks on <a href="Machine_learning" title="Machine learning">machine learning</a> algorithms, and of the defenses against such attacks.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> A survey from May 2020 revealed practitioners' common feeling for better protection of machine learning systems in industrial applications.<sup id="cite_ref-:1_2-0" class="reference"><a href="#cite_note-:1-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p><p>Machine learning techniques are mostly designed to work on specific problem sets, under the assumption that the training and test data are generated from the same statistical distribution (<a href="Independent_and_identically_distributed_random_variables" title="Independent and identically distributed random variables">IID</a>). However, this assumption is often dangerously violated in practical high-stake applications, where users may intentionally supply fabricated data that violates the statistical assumption.
</p><p>Most common attacks in adversarial machine learning include <a href="Evasion_attack" class="mw-redirect" title="Evasion attack">evasion attacks</a>,<sup id="cite_ref-GoodfellowMcDaniel20182_3-0" class="reference"><a href="#cite_note-GoodfellowMcDaniel20182-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> <a href="Data_poisoning_attack" class="mw-redirect" title="Data poisoning attack">data poisoning attacks</a>,<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> <a href="Byzantine_attack" class="mw-redirect" title="Byzantine attack">Byzantine attacks</a><sup id="cite_ref-:13_5-0" class="reference"><a href="#cite_note-:13-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> and model extraction.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="History">History</h2></div>
<p>At the MIT Spam Conference in January 2004, <a href="John_Graham-Cumming" title="John Graham-Cumming">John Graham-Cumming</a> showed that a machine-learning spam filter could be used to defeat another machine-learning spam filter by automatically learning which words to add to a spam email to get the email classified as not spam.<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p><p>In 2004, Nilesh Dalvi and others noted that <a href="Linear_classifier" title="Linear classifier">linear classifiers</a> used in <a href="Email_filtering" title="Email filtering">spam filters</a> could be defeated by simple "<a href="Evasion_(network_security)" title="Evasion (network security)">evasion</a> attacks" as spammers inserted "good words" into their spam emails. (Around 2007, some spammers added random noise to fuzz words within "image spam" in order to defeat <a href="Optical_character_recognition" title="Optical character recognition">OCR</a>-based filters.) In 2006, Marco Barreno and others published "Can Machine Learning Be Secure?", outlining a broad taxonomy of attacks. As late as 2013 many researchers continued to hope that non-linear classifiers (such as <a href="Support_vector_machine" title="Support vector machine">support vector machines</a> and <a href="Neural_networks" class="mw-redirect" title="Neural networks">neural networks</a>) might be robust to adversaries, until Battista Biggio and others demonstrated the first gradient-based attacks on such machine-learning models (2012<sup id="cite_ref-Poisoning_Attacks_against_Support_V_8-0" class="reference"><a href="#cite_note-Poisoning_Attacks_against_Support_V-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>–2013<sup id="cite_ref-Springer_9-0" class="reference"><a href="#cite_note-Springer-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>). In 2012, <a href="Deep_learning" title="Deep learning">deep neural networks</a> began to dominate computer vision problems; starting in 2014, Christian Szegedy and others demonstrated that deep neural networks could be fooled by adversaries, again using a gradient-based attack to craft adversarial perturbations.<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:02_11-0" class="reference"><a href="#cite_note-:02-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</p><p>Recently, it was observed that adversarial attacks are harder to produce in the practical world due to the different environmental constraints that cancel out the effect of noise.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> For example, any small rotation or slight illumination on an adversarial image can destroy the adversariality. In addition, researchers such as Google Brain's Nick Frosst point out that it is much easier to make self-driving cars<sup id="cite_ref-LimTaeihagh20192_14-0" class="reference"><a href="#cite_note-LimTaeihagh20192-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> miss stop signs by physically removing the sign itself, rather than creating adversarial examples.<sup id="cite_ref-:2_15-0" class="reference"><a href="#cite_note-:2-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> Frosst also believes that the adversarial machine learning community incorrectly assumes models trained on a certain data distribution will also perform well on a completely different data distribution. He suggests that a new approach to machine learning should be explored, and is currently working on a unique neural network that has characteristics more similar to human perception than state-of-the-art approaches.<sup id="cite_ref-:2_15-1" class="reference"><a href="#cite_note-:2-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>
</p><p>While adversarial machine learning continues to be heavily rooted in academia, large tech companies such as Google, Microsoft, and IBM have begun curating documentation and open source code bases to allow others to concretely assess the <a href="Robustness_(computer_science)" title="Robustness (computer science)">robustness</a> of machine learning models and minimize the risk of adversarial attacks.<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:3_17-0" class="reference"><a href="#cite_note-:3-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Examples">Examples</h3></div>
<p>Examples include attacks in <a href="Spam_filtering" class="mw-redirect" title="Spam filtering">spam filtering</a>, where spam messages are obfuscated through the misspelling of "bad" words or the insertion of "good" words;<sup id="cite_ref-BiggioFumera20102_19-0" class="reference"><a href="#cite_note-BiggioFumera20102-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_18A2_20-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_18A2-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup> attacks in <a href="Computer_security" title="Computer security">computer security</a>, such as obfuscating malware code within <a href="Network_packet" title="Network packet">network packets</a> or modifying the characteristics of a <a href="Traffic_flow_(computer_networking)" title="Traffic flow (computer networking)">network flow</a> to mislead intrusion detection;<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:0_22-0" class="reference"><a href="#cite_note-:0-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup> attacks in biometric recognition where fake biometric traits may be exploited to impersonate a legitimate user;<sup id="cite_ref-RodriguesLing20092_23-0" class="reference"><a href="#cite_note-RodriguesLing20092-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup> or to compromise users' template galleries that adapt to updated traits over time.
</p><p>Researchers showed that by changing only one-pixel it was possible to fool deep learning algorithms.<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup> Others <a href="3-D_print" class="mw-redirect" title="3-D print">3-D printed</a> a toy turtle with a texture engineered to make Google's object detection <a href="Artificial_intelligence" title="Artificial intelligence">AI</a> classify it as a rifle regardless of the angle from which the turtle was viewed.<sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> Creating the turtle required only low-cost commercially available 3-D printing technology.<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
</p><p>A machine-tweaked image of a dog was shown to look like a cat to both computers and humans.<sup id="cite_ref-27" class="reference"><a href="#cite_note-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup> A 2019 study reported that humans can guess how machines will classify adversarial images.<sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup> Researchers discovered methods for perturbing the appearance of a stop sign such that an autonomous vehicle classified it as a merge or speed limit sign.<sup id="cite_ref-LimTaeihagh20192_14-1" class="reference"><a href="#cite_note-LimTaeihagh20192-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-29" class="reference"><a href="#cite_note-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup>
</p><p>A data poisoning filter called Nightshade was released in 2023 by researchers at the <a href="University_of_Chicago" title="University of Chicago">University of Chicago</a>. It was created for use by <a href="Artist" title="Artist">visual artists</a> to put on their artwork to corrupt the data set of <a href="Text-to-image_model" title="Text-to-image model">text-to-image models</a>, which usually scrape their data from the internet without the consent of the image creator.<sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup>
</p><p><a href="McAfee" title="McAfee">McAfee</a> attacked <a href="Tesla%2C_Inc." title="Tesla, Inc.">Tesla</a>'s former <a href="Mobileye" title="Mobileye">Mobileye</a> system, fooling it into driving 50 mph over the speed limit, simply by adding a two-inch strip of black tape to a speed limit sign.<sup id="cite_ref-32" class="reference"><a href="#cite_note-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup>
</p><p>Adversarial patterns on glasses or clothing designed to deceive facial-recognition systems or license-plate readers, have led to a niche industry of "stealth streetwear".<sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup>
</p><p>An adversarial attack on a neural network can allow an attacker to inject algorithms into the target system.<sup id="cite_ref-nature_why2_35-0" class="reference"><a href="#cite_note-nature_why2-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup> Researchers can also create adversarial audio inputs to disguise commands to intelligent assistants in benign-seeming audio;<sup id="cite_ref-36" class="reference"><a href="#cite_note-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup> a parallel literature explores human perception of such stimuli.<sup id="cite_ref-37" class="reference"><a href="#cite_note-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-38" class="reference"><a href="#cite_note-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup>
</p><p>Clustering algorithms are used in security applications. Malware and <a href="Computer_viruses" class="mw-redirect" title="Computer viruses">computer virus</a> analysis aims to identify malware families, and to generate specific detection signatures.<sup id="cite_ref-Adversarial_Machine_Learning_42A2_39-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_42A2-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_46A2_40-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_46A2-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Attack_modalities">Attack modalities</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Taxonomy">Taxonomy</h3></div>
<p>Attacks against (supervised) machine learning algorithms have been categorized along three primary axes:<sup id="cite_ref-Adversarial_Machine_Learning_22_41-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_22-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup> influence on the classifier, the security violation and their specificity.
</p>
<ul><li>Classifier influence: An attack can influence the classifier by disrupting the classification phase. This may be preceded by an exploration phase to identify vulnerabilities. The attacker's capabilities might be restricted by the presence of data manipulation constraints.<sup id="cite_ref-42" class="reference"><a href="#cite_note-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup></li>
<li>Security violation: An attack can supply malicious data that gets classified as legitimate. Malicious data supplied during training can cause legitimate data to be rejected after training.</li>
<li>Specificity: A targeted attack attempts to allow a specific intrusion/disruption. Alternatively, an indiscriminate attack creates general mayhem.</li></ul>
<p>This taxonomy has been extended into a more comprehensive threat model that allows explicit assumptions about the adversary's goal, knowledge of the attacked system, capability of manipulating the input data/system components, and on attack strategy.<sup id="cite_ref-Adversarial_Machine_Learning_4A2_43-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_4A2-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_5A2_44-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_5A2-44"><span class="cite-bracket">[</span>44<span class="cite-bracket">]</span></a></sup> This taxonomy has further been extended to include dimensions for defense strategies against adversarial attacks.<sup id="cite_ref-45" class="reference"><a href="#cite_note-45"><span class="cite-bracket">[</span>45<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Strategies">Strategies</h3></div>
<p>Below are some of the most commonly encountered attack scenarios.
</p>
<div class="mw-heading mw-heading4"><h4 id="Data_poisoning">Data poisoning</h4></div>
<p>Poisoning consists of contaminating the training dataset with data designed to increase errors in the output. Given that learning algorithms are shaped by their training datasets, poisoning can effectively reprogram algorithms with potentially malicious intent. Concerns have been raised especially for user-generated training data, e.g. for content recommendation or natural language models. The ubiquity of fake accounts offers many opportunities for poisoning. Facebook reportedly removes around 7 billion fake accounts per year.<sup id="cite_ref-46" class="reference"><a href="#cite_note-46"><span class="cite-bracket">[</span>46<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-47" class="reference"><a href="#cite_note-47"><span class="cite-bracket">[</span>47<span class="cite-bracket">]</span></a></sup> Poisoning has been reported as the leading concern for industrial applications.<sup id="cite_ref-:1_2-1" class="reference"><a href="#cite_note-:1-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p><p>On social medias, <a href="Disinformation" title="Disinformation">disinformation campaigns</a> attempt to bias recommendation and moderation algorithms, to push certain content over others.
</p><p>A particular case of data poisoning is the <a href="Backdoor_(computing)" title="Backdoor (computing)">backdoor</a> attack,<sup id="cite_ref-48" class="reference"><a href="#cite_note-48"><span class="cite-bracket">[</span>48<span class="cite-bracket">]</span></a></sup> which aims to teach a specific behavior for inputs with a given trigger, e.g. a small defect on images, sounds, videos or texts.
</p>
<p>For instance, <a href="Intrusion_detection_system" title="Intrusion detection system">intrusion detection systems</a> are often trained using collected data. An attacker may poison this data by injecting malicious samples during operation that subsequently disrupt retraining.<sup id="cite_ref-Adversarial_Machine_Learning_4A2_43-1" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_4A2-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_5A2_44-1" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_5A2-44"><span class="cite-bracket">[</span>44<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_22_41-1" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_22-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_15A2_50-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_15A2-50"><span class="cite-bracket">[</span>50<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_29A2_51-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_29A2-51"><span class="cite-bracket">[</span>51<span class="cite-bracket">]</span></a></sup>
</p><p>Data poisoning techniques can also be applied to <a href="Text-to-image_model" title="Text-to-image model">text-to-image models</a> to alter their output, which is used by artists to defend their copyrighted works or their artistic style against imitation.<sup id="cite_ref-52" class="reference"><a href="#cite_note-52"><span class="cite-bracket">[</span>52<span class="cite-bracket">]</span></a></sup>
</p><p>Data poisoning can also happen unintentionally through <a href="Model_collapse" title="Model collapse">model collapse</a>, where models are trained on synthetic data.<sup id="cite_ref-53" class="reference"><a href="#cite_note-53"><span class="cite-bracket">[</span>53<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading4"><h4 id="Byzantine_attacks">Byzantine attacks</h4></div>
<p>As machine learning is scaled, it often relies on multiple computing machines. In <a href="Federated_learning" title="Federated learning">federated learning</a>, for instance, edge devices collaborate with a central server, typically by sending gradients or model parameters. However, some of these devices may deviate from their expected behavior, e.g. to harm the central server's model<sup id="cite_ref-Baruch_2019_54-0" class="reference"><a href="#cite_note-Baruch_2019-54"><span class="cite-bracket">[</span>54<span class="cite-bracket">]</span></a></sup> or to bias algorithms towards certain behaviors (e.g., amplifying the recommendation of disinformation content). On the other hand, if the training is performed on a single machine, then the model is very vulnerable to a failure of the machine, or an attack on the machine; the machine is a <a href="Single_point_of_failure" title="Single point of failure">single point of failure</a>.<sup id="cite_ref-55" class="reference"><a href="#cite_note-55"><span class="cite-bracket">[</span>55<span class="cite-bracket">]</span></a></sup> In fact, the machine owner may themselves insert provably undetectable <a href="Backdoor_(computing)" title="Backdoor (computing)">backdoors</a>.<sup id="cite_ref-56" class="reference"><a href="#cite_note-56"><span class="cite-bracket">[</span>56<span class="cite-bracket">]</span></a></sup>
</p><p>The current leading solutions to make (distributed) learning algorithms provably resilient to a minority of malicious (a.k.a. <a href="Byzantine_fault" title="Byzantine fault">Byzantine</a>) participants are based on robust gradient aggregation rules.<sup id="cite_ref-:14_57-0" class="reference"><a href="#cite_note-:14-57"><span class="cite-bracket">[</span>57<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-58" class="reference"><a href="#cite_note-58"><span class="cite-bracket">[</span>58<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-59" class="reference"><a href="#cite_note-59"><span class="cite-bracket">[</span>59<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-60" class="reference"><a href="#cite_note-60"><span class="cite-bracket">[</span>60<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-61" class="reference"><a href="#cite_note-61"><span class="cite-bracket">[</span>61<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-62" class="reference"><a href="#cite_note-62"><span class="cite-bracket">[</span>62<span class="cite-bracket">]</span></a></sup> The robust aggregation rules do not always work especially when the data across participants has a non-iid distribution. Nevertheless, in the context of heterogeneous honest participants, such as users with different consumption habits for recommendation algorithms or writing styles for language models, there are provable impossibility theorems on what any robust learning algorithm can guarantee.<sup id="cite_ref-:13_5-1" class="reference"><a href="#cite_note-:13-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-63" class="reference"><a href="#cite_note-63"><span class="cite-bracket">[</span>63<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading4"><h4 id="Evasion">Evasion</h4></div>
<p>Evasion attacks<sup id="cite_ref-Springer_9-1" class="reference"><a href="#cite_note-Springer-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_4A2_43-2" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_4A2-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_5A2_44-2" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_5A2-44"><span class="cite-bracket">[</span>44<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_36A2_64-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_36A2-64"><span class="cite-bracket">[</span>64<span class="cite-bracket">]</span></a></sup> consist of exploiting the imperfection of a trained model. For instance, spammers and hackers often attempt to evade detection by obfuscating the content of spam emails and <a href="Malware" title="Malware">malware</a>. Samples are modified to evade detection; that is, to be classified as legitimate. This does not involve influence over the training data. A clear example of evasion is <a href="Image_spam" title="Image spam">image-based spam</a> in which the spam content is embedded within an attached image to evade textual analysis by anti-spam filters. Another example of evasion is given by spoofing attacks against biometric verification systems.<sup id="cite_ref-RodriguesLing20092_23-1" class="reference"><a href="#cite_note-RodriguesLing20092-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
</p><p>Evasion attacks can be generally split into two different categories: <a href="Black_box" title="Black box">black box attacks</a> and <a href="White_box_(software_engineering)" title="White box (software engineering)">white box attacks</a>.<sup id="cite_ref-:3_17-1" class="reference"><a href="#cite_note-:3-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading4"><h4 id="Model_extraction">Model extraction</h4></div>
<p>Model extraction involves an adversary probing a black box machine learning system in order to extract the data it was trained on.<sup id="cite_ref-65" class="reference"><a href="#cite_note-65"><span class="cite-bracket">[</span>65<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:12_66-0" class="reference"><a href="#cite_note-:12-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup> This can cause issues when either the training data or the model itself is sensitive and confidential. For example, model extraction could be used to extract a proprietary stock trading model which the adversary could then use for their own financial benefit.
</p><p>In the extreme case, model extraction can lead to <b>model stealing</b>, which corresponds to extracting a sufficient amount of data from the model to enable the complete reconstruction of the model.
</p><p>On the other hand, membership inference is a targeted model extraction attack, which infers the owner of a data point, often by leveraging the <a href="Overfitting" title="Overfitting">overfitting</a> resulting from poor machine learning practices.<sup id="cite_ref-:6_67-0" class="reference"><a href="#cite_note-:6-67"><span class="cite-bracket">[</span>67<span class="cite-bracket">]</span></a></sup> Concerningly, this is sometimes achievable even without knowledge or access to a target model's parameters, raising security concerns for models trained on sensitive data, including but not limited to medical records and/or personally identifiable information. With the emergence of <a href="Transfer_learning" title="Transfer learning">transfer learning</a> and public accessibility of many state of the art machine learning models, tech companies are increasingly drawn to create models based on public ones, giving attackers freely accessible information to the structure and type of model being used.<sup id="cite_ref-:6_67-1" class="reference"><a href="#cite_note-:6-67"><span class="cite-bracket">[</span>67<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Categories">Categories</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Adversarial_attacks_and_training_in_linear_models">Adversarial attacks and training in linear models</h3></div>
<p>There is a growing literature about adversarial attacks in
linear models. Indeed, since the seminal work from Goodfellow at al.<sup id="cite_ref-68" class="reference"><a href="#cite_note-68"><span class="cite-bracket">[</span>68<span class="cite-bracket">]</span></a></sup> studying these models in linear models has been an important tool to understand how adversarial attacks affect machine learning models.
The analysis of these models is simplified because the computation of adversarial attacks can be simplified in linear regression and classification problems. Moreover, adversarial training is convex in this case.<sup id="cite_ref-69" class="reference"><a href="#cite_note-69"><span class="cite-bracket">[</span>69<span class="cite-bracket">]</span></a></sup>
</p><p>Linear models allow for analytical analysis while still reproducing phenomena observed in state-of-the-art models.
One prime example of that is how this model can be used to explain the trade-off between robustness and accuracy.<sup id="cite_ref-70" class="reference"><a href="#cite_note-70"><span class="cite-bracket">[</span>70<span class="cite-bracket">]</span></a></sup>
Diverse work indeed provides analysis of adversarial attacks in linear models, including asymptotic analysis for classification <sup id="cite_ref-71" class="reference"><a href="#cite_note-71"><span class="cite-bracket">[</span>71<span class="cite-bracket">]</span></a></sup> and for linear regression.<sup id="cite_ref-72" class="reference"><a href="#cite_note-72"><span class="cite-bracket">[</span>72<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-73" class="reference"><a href="#cite_note-73"><span class="cite-bracket">[</span>73<span class="cite-bracket">]</span></a></sup> And, finite-sample analysis based on Rademacher complexity.<sup id="cite_ref-74" class="reference"><a href="#cite_note-74"><span class="cite-bracket">[</span>74<span class="cite-bracket">]</span></a></sup>
</p><p>A result from studying adversarial attacks in linear models is that it closely relates to <a href="Regularization_(mathematics)" title="Regularization (mathematics)">regularization</a>.<sup id="cite_ref-75" class="reference"><a href="#cite_note-75"><span class="cite-bracket">[</span>75<span class="cite-bracket">]</span></a></sup> Under certain conditions, it has been shown that
</p>
<ul><li>adversarial training of a linear regression model with input perturbations restricted by the <i>infinity-norm</i> closely resembles <a href="Lasso_(statistics)" title="Lasso (statistics)">Lasso</a> regression, and that</li>
<li>adversarial training of a linear regression model with input perturbations restricted by the <i>2-norm</i> closely resembles <a href="Ridge_regression" title="Ridge regression">Ridge regression</a>.</li></ul>
<div class="mw-heading mw-heading3"><h3 id="Adversarial_deep_reinforcement_learning">Adversarial deep reinforcement learning</h3></div>
<p>Adversarial deep reinforcement learning is an active area of research in reinforcement learning focusing on vulnerabilities of learned policies. In this research area, some studies initially showed that reinforcement learning policies are susceptible to imperceptible adversarial manipulations.<sup id="cite_ref-76" class="reference"><a href="#cite_note-76"><span class="cite-bracket">[</span>76<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-77" class="reference"><a href="#cite_note-77"><span class="cite-bracket">[</span>77<span class="cite-bracket">]</span></a></sup> While some methods have been proposed to overcome these susceptibilities, in the most recent studies it has been shown that these proposed solutions are far from providing an accurate representation of current vulnerabilities of deep reinforcement learning policies.<sup id="cite_ref-78" class="reference"><a href="#cite_note-78"><span class="cite-bracket">[</span>78<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Adversarial_natural_language_processing">Adversarial natural language processing</h3></div>
<p>Adversarial attacks on <a href="Speech_recognition" title="Speech recognition">speech recognition</a> have been introduced for speech-to-text applications, in particular for Mozilla's implementation of DeepSpeech.<sup id="cite_ref-79" class="reference"><a href="#cite_note-79"><span class="cite-bracket">[</span>79<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Specific_attack_types">Specific attack types</h2></div>
<p>There are a large variety of different adversarial attacks that can be used against machine learning systems. Many of these work on both <a href="Deep_learning" title="Deep learning">deep learning</a> systems as well as traditional machine learning models such as <a href="Support_vector_machine" title="Support vector machine">SVMs</a><sup id="cite_ref-Poisoning_Attacks_against_Support_V_8-1" class="reference"><a href="#cite_note-Poisoning_Attacks_against_Support_V-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> and <a href="Linear_regression" title="Linear regression">linear regression</a>.<sup id="cite_ref-80" class="reference"><a href="#cite_note-80"><span class="cite-bracket">[</span>80<span class="cite-bracket">]</span></a></sup> A high level sample of these attack types include:
</p>
<ul><li>Adversarial Examples<sup id="cite_ref-81" class="reference"><a href="#cite_note-81"><span class="cite-bracket">[</span>81<span class="cite-bracket">]</span></a></sup></li>
<li>Trojan Attacks / Backdoor Attacks<sup id="cite_ref-82" class="reference"><a href="#cite_note-82"><span class="cite-bracket">[</span>82<span class="cite-bracket">]</span></a></sup></li>
<li>Model Inversion<sup id="cite_ref-83" class="reference"><a href="#cite_note-83"><span class="cite-bracket">[</span>83<span class="cite-bracket">]</span></a></sup></li>
<li>Membership Inference<sup id="cite_ref-84" class="reference"><a href="#cite_note-84"><span class="cite-bracket">[</span>84<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading3"><h3 id="Adversarial_examples">Adversarial examples</h3></div>
<p>An adversarial example refers to specially crafted input that is designed to look "normal" to humans but causes misclassification to a machine learning model. Often, a form of specially designed "noise" is used to elicit the misclassifications. Below are some current techniques for generating adversarial examples in the literature (by no means an exhaustive list).
</p>
<ul><li>Gradient-based evasion attack<sup id="cite_ref-Springer_9-2" class="reference"><a href="#cite_note-Springer-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup></li>
<li>Fast Gradient Sign Method (FGSM)<sup id="cite_ref-Explaining_and_Harnessing_Adversari2_85-0" class="reference"><a href="#cite_note-Explaining_and_Harnessing_Adversari2-85"><span class="cite-bracket">[</span>85<span class="cite-bracket">]</span></a></sup></li>
<li>Projected Gradient Descent (PGD)<sup id="cite_ref-86" class="reference"><a href="#cite_note-86"><span class="cite-bracket">[</span>86<span class="cite-bracket">]</span></a></sup></li>
<li>Carlini and Wagner (C&W) attack<sup id="cite_ref-87" class="reference"><a href="#cite_note-87"><span class="cite-bracket">[</span>87<span class="cite-bracket">]</span></a></sup></li>
<li>Adversarial patch attack<sup id="cite_ref-88" class="reference"><a href="#cite_note-88"><span class="cite-bracket">[</span>88<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading4"><h4 id="Black_box_attacks">Black box attacks</h4></div>
<p>Black box attacks in adversarial machine learning assume that the adversary can only get outputs for provided inputs and has no knowledge of the model structure or parameters.<sup id="cite_ref-:3_17-2" class="reference"><a href="#cite_note-:3-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-89" class="reference"><a href="#cite_note-89"><span class="cite-bracket">[</span>89<span class="cite-bracket">]</span></a></sup> In this case, the adversarial example is generated either using a model created from scratch, or without any model at all (excluding the ability to query the original model). In either case, the objective of these attacks is to create adversarial examples that are able to transfer to the black box model in question.<sup id="cite_ref-:4_90-0" class="reference"><a href="#cite_note-:4-90"><span class="cite-bracket">[</span>90<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading5"><h5 id="Simple_Black-box_Adversarial_Attacks">Simple Black-box Adversarial Attacks</h5></div>
<p><i>Simple Black-box Adversarial Attacks</i> is a query-efficient way to attack black-box image classifiers.<sup id="cite_ref-91" class="reference"><a href="#cite_note-91"><span class="cite-bracket">[</span>91<span class="cite-bracket">]</span></a></sup> </p><blockquote><p>Take a random orthonormal basis <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle v_{1},v_{2},\dots ,v_{d}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>,</mo>
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>,</mo>
<mo>…<!-- … --></mo>
<mo>,</mo>
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>d</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle v_{1},v_{2},\dots ,v_{d}}</annotation>
</semantics>
</math></span><img src="./f4ef047a12d85c1067cd06cf6d9dc7ef551032b5.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:12.795ex; height:2.009ex;" alt="{\displaystyle v_{1},v_{2},\dots ,v_{d}}" loading="lazy"></span> in <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \mathbb {R} ^{d}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">R</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>d</mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \mathbb {R} ^{d}}</annotation>
</semantics>
</math></span><img src="./a713426956296f1668fce772df3c60b9dde8a685.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.77ex; height:2.676ex;" alt="{\displaystyle \mathbb {R} ^{d}}" loading="lazy"></span>. The authors suggested the <a href="Discrete_cosine_transform" title="Discrete cosine transform">discrete cosine transform</a> of the standard basis (the pixels).
</p><p>For a correctly classified image <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x}</annotation>
</semantics>
</math></span><img src="./87f9e315fd7e2ba406057a97300593c4802b53e4.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\displaystyle x}" loading="lazy"></span>, try <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x+\epsilon v_{1},x-\epsilon v_{1}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>x</mi>
<mo>+</mo>
<mi>ϵ<!-- ϵ --></mi>
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>,</mo>
<mi>x</mi>
<mo>−<!-- − --></mo>
<mi>ϵ<!-- ϵ --></mi>
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x+\epsilon v_{1},x-\epsilon v_{1}}</annotation>
</semantics>
</math></span><img src="./945eb5aa601d41be8b9537fd27f07acf7a646876.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:15.626ex; height:2.343ex;" alt="{\displaystyle x+\epsilon v_{1},x-\epsilon v_{1}}" loading="lazy"></span>, and compare the amount of error in the classifier upon <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x+\epsilon v_{1},x,x-\epsilon v_{1}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>x</mi>
<mo>+</mo>
<mi>ϵ<!-- ϵ --></mi>
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>,</mo>
<mi>x</mi>
<mo>,</mo>
<mi>x</mi>
<mo>−<!-- − --></mo>
<mi>ϵ<!-- ϵ --></mi>
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x+\epsilon v_{1},x,x-\epsilon v_{1}}</annotation>
</semantics>
</math></span><img src="./bda6a8b14486c3314c411dd8a3e92c5c900ca085.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:17.99ex; height:2.343ex;" alt="{\displaystyle x+\epsilon v_{1},x,x-\epsilon v_{1}}" loading="lazy"></span>. Pick the one that causes the largest amount of error.
</p><p>
Repeat this for <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle v_{2},v_{3},\dots }">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>,</mo>
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
<mo>,</mo>
<mo>…<!-- … --></mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle v_{2},v_{3},\dots }</annotation>
</semantics>
</math></span><img src="./f95f688db0c6bcc04da141bff2fe91791ae2c984.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:9.155ex; height:2.009ex;" alt="{\displaystyle v_{2},v_{3},\dots }" loading="lazy"></span> until the desired level of error in the classifier is reached.</p></blockquote><p>It was discovered when the authors designed a simple baseline to compare with a previous black-box adversarial attack algorithm based on <a href="Gaussian_process" title="Gaussian process">gaussian processes</a>, and were surprised that the baseline worked even better.<sup id="cite_ref-92" class="reference"><a href="#cite_note-92"><span class="cite-bracket">[</span>92<span class="cite-bracket">]</span></a></sup>
</p><div class="mw-heading mw-heading5"><h5 id="Square_Attack">Square Attack</h5></div>
<p>The Square Attack was introduced in 2020 as a black box evasion adversarial attack based on querying classification scores without the need of gradient information.<sup id="cite_ref-:7_93-0" class="reference"><a href="#cite_note-:7-93"><span class="cite-bracket">[</span>93<span class="cite-bracket">]</span></a></sup> As a score based black box attack, this adversarial approach is able to query probability distributions across model output classes, but has no other access to the model itself. According to the paper's authors, the proposed Square Attack required fewer queries than when compared to state-of-the-art score-based black box attacks at the time.<sup id="cite_ref-:7_93-1" class="reference"><a href="#cite_note-:7-93"><span class="cite-bracket">[</span>93<span class="cite-bracket">]</span></a></sup>
</p><p>To describe the function objective, the attack defines the classifier as <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle f:[0,1]^{d}\rightarrow \mathbb {R} ^{K}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>f</mi>
<mo>:</mo>
<mo stretchy="false">[</mo>
<mn>0</mn>
<mo>,</mo>
<mn>1</mn>
<msup>
<mo stretchy="false">]</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>d</mi>
</mrow>
</msup>
<mo stretchy="false">→<!-- → --></mo>
<msup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">R</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>K</mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle f:[0,1]^{d}\rightarrow \mathbb {R} ^{K}}</annotation>
</semantics>
</math></span><img src="./e3472a47f3e7d027dc8c1eb37153474a4605834a.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:15.946ex; height:3.176ex;" alt="{\textstyle f:[0,1]^{d}\rightarrow \mathbb {R} ^{K}}" loading="lazy"></span>, with <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle d}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>d</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle d}</annotation>
</semantics>
</math></span><img src="./252135f29da0e9f9e130ff2d53be5df2f7044d99.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.216ex; height:2.176ex;" alt="{\textstyle d}" loading="lazy"></span> representing the dimensions of the input and <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle K}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>K</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle K}</annotation>
</semantics>
</math></span><img src="./985dcc2532a2d4d91b9a9610139216c63cf832d0.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.066ex; height:2.176ex;" alt="{\textstyle K}" loading="lazy"></span> as the total number of output classes. <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle f_{k}(x)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msub>
<mi>f</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>k</mi>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle f_{k}(x)}</annotation>
</semantics>
</math></span><img src="./401eb4a087028d07f52aa568ffb7b5a4bf9c9d59.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:5.367ex; height:2.843ex;" alt="{\textstyle f_{k}(x)}" loading="lazy"></span> returns the score (or a probability between 0 and 1) that the input <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> belongs to class <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle k}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>k</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle k}</annotation>
</semantics>
</math></span><img src="./0d5595fc0c47452f8fc2aa6e29c3611f047714b0.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.211ex; height:2.176ex;" alt="{\textstyle k}" loading="lazy"></span>, which allows the classifier's class output for any input <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> to be defined as <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle {\text{argmax}}_{k=1,...,K}f_{k}(x)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mtext>argmax</mtext>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>k</mi>
<mo>=</mo>
<mn>1</mn>
<mo>,</mo>
<mo>.</mo>
<mo>.</mo>
<mo>.</mo>
<mo>,</mo>
<mi>K</mi>
</mrow>
</msub>
<msub>
<mi>f</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>k</mi>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle {\text{argmax}}_{k=1,...,K}f_{k}(x)}</annotation>
</semantics>
</math></span><img src="./7c022135096f75cfdec5f9caca8742d424e322e7.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.171ex; width:19.866ex; height:3.176ex;" alt="{\textstyle {\text{argmax}}_{k=1,...,K}f_{k}(x)}" loading="lazy"></span>. The goal of this attack is as follows:<sup id="cite_ref-:7_93-2" class="reference"><a href="#cite_note-:7-93"><span class="cite-bracket">[</span>93<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\text{argmax}}_{k=1,...,K}f_{k}({\hat {x}})\neq y,||{\hat {x}}-x||_{p}\leq \epsilon {\text{ and }}{\hat {x}}\in [0,1]^{d}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mtext>argmax</mtext>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>k</mi>
<mo>=</mo>
<mn>1</mn>
<mo>,</mo>
<mo>.</mo>
<mo>.</mo>
<mo>.</mo>
<mo>,</mo>
<mi>K</mi>
</mrow>
</msub>
<msub>
<mi>f</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>k</mi>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">)</mo>
<mo>≠<!-- ≠ --></mo>
<mi>y</mi>
<mo>,</mo>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo>−<!-- − --></mo>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>p</mi>
</mrow>
</msub>
<mo>≤<!-- ≤ --></mo>
<mi>ϵ<!-- ϵ --></mi>
<mrow class="MJX-TeXAtom-ORD">
<mtext> and </mtext>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo>∈<!-- ∈ --></mo>
<mo stretchy="false">[</mo>
<mn>0</mn>
<mo>,</mo>
<mn>1</mn>
<msup>
<mo stretchy="false">]</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>d</mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\text{argmax}}_{k=1,...,K}f_{k}({\hat {x}})\neq y,||{\hat {x}}-x||_{p}\leq \epsilon {\text{ and }}{\hat {x}}\in [0,1]^{d}}</annotation>
</semantics>
</math></span></span>
</p><p>In other words, finding some perturbed adversarial example <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle {\hat {x}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle {\hat {x}}}</annotation>
</semantics>
</math></span><img src="./90c4733eaf111a6ed5e884a5c3d369a62d8db77f.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:2.176ex;" alt="{\textstyle {\hat {x}}}" loading="lazy"></span> such that the classifier incorrectly classifies it to some other class under the constraint that <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle {\hat {x}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle {\hat {x}}}</annotation>
</semantics>
</math></span><img src="./90c4733eaf111a6ed5e884a5c3d369a62d8db77f.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:2.176ex;" alt="{\textstyle {\hat {x}}}" loading="lazy"></span> and <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> are similar. The paper then defines <a href="Loss_functions_for_classification" title="Loss functions for classification">loss</a> <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle L}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>L</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle L}</annotation>
</semantics>
</math></span><img src="./8fb88de7e4d31737dae8f02575033272f29e6720.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.583ex; height:2.176ex;" alt="{\textstyle L}" loading="lazy"></span> as <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle L(f({\hat {x}}),y)=f_{y}({\hat {x}})-\max _{k\neq y}f_{k}({\hat {x}})}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>L</mi>
<mo stretchy="false">(</mo>
<mi>f</mi>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">)</mo>
<mo>,</mo>
<mi>y</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<msub>
<mi>f</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>y</mi>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">)</mo>
<mo>−<!-- − --></mo>
<munder>
<mo movablelimits="true" form="prefix">max</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>k</mi>
<mo>≠<!-- ≠ --></mo>
<mi>y</mi>
</mrow>
</munder>
<msub>
<mi>f</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>k</mi>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle L(f({\hat {x}}),y)=f_{y}({\hat {x}})-\max _{k\neq y}f_{k}({\hat {x}})}</annotation>
</semantics>
</math></span><img src="./97b4a97cb8631f94c4feb497dac7c6269a4a59e3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:34.53ex; height:3.009ex;" alt="{\textstyle L(f({\hat {x}}),y)=f_{y}({\hat {x}})-\max _{k\neq y}f_{k}({\hat {x}})}" loading="lazy"></span> and proposes the solution to finding adversarial example <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle {\hat {x}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle {\hat {x}}}</annotation>
</semantics>
</math></span><img src="./90c4733eaf111a6ed5e884a5c3d369a62d8db77f.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:2.176ex;" alt="{\textstyle {\hat {x}}}" loading="lazy"></span> as solving the below <a href="Constrained_optimization_problem" class="mw-redirect" title="Constrained optimization problem">constrained optimization problem</a>:<sup id="cite_ref-:7_93-3" class="reference"><a href="#cite_note-:7-93"><span class="cite-bracket">[</span>93<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \min _{{\hat {x}}\in [0,1]^{d}}L(f({\hat {x}}),y),{\text{ s.t. }}||{\hat {x}}-x||_{p}\leq \epsilon }">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<munder>
<mo movablelimits="true" form="prefix">min</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo>∈<!-- ∈ --></mo>
<mo stretchy="false">[</mo>
<mn>0</mn>
<mo>,</mo>
<mn>1</mn>
<msup>
<mo stretchy="false">]</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>d</mi>
</mrow>
</msup>
</mrow>
</munder>
<mi>L</mi>
<mo stretchy="false">(</mo>
<mi>f</mi>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">)</mo>
<mo>,</mo>
<mi>y</mi>
<mo stretchy="false">)</mo>
<mo>,</mo>
<mrow class="MJX-TeXAtom-ORD">
<mtext> s.t. </mtext>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo>−<!-- − --></mo>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>p</mi>
</mrow>
</msub>
<mo>≤<!-- ≤ --></mo>
<mi>ϵ<!-- ϵ --></mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \min _{{\hat {x}}\in [0,1]^{d}}L(f({\hat {x}}),y),{\text{ s.t. }}||{\hat {x}}-x||_{p}\leq \epsilon }</annotation>
</semantics>
</math></span></span>
</p><p>The result in theory is an adversarial example that is highly confident in the incorrect class but is also very similar to the original image. To find such example, Square Attack utilizes the iterative <a href="Random_search" title="Random search">random search</a> technique to randomly perturb the image in hopes of improving the objective function. In each step, the algorithm perturbs only a small square section of pixels, hence the name Square Attack, which terminates as soon as an adversarial example is found in order to improve query efficiency. Finally, since the attack algorithm uses scores and not gradient information, the authors of the paper indicate that this approach is not affected by gradient masking, a common technique formerly used to prevent evasion attacks.<sup id="cite_ref-:7_93-4" class="reference"><a href="#cite_note-:7-93"><span class="cite-bracket">[</span>93<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading5"><h5 id="HopSkipJump_Attack">HopSkipJump Attack</h5></div>
<p>This black box attack was also proposed as a query efficient attack, but one that relies solely on access to any input's predicted output class. In other words, the HopSkipJump attack does not require the ability to calculate gradients or access to score values like the Square Attack, and will require just the model's class prediction output (for any given input). The proposed attack is split into two different settings, targeted and untargeted, but both are built from the general idea of adding minimal perturbations that leads to a different model output. In the targeted setting, the goal is to cause the model to misclassify the perturbed image to a specific target label (that is not the original label). In the untargeted setting, the goal is to cause the model to misclassify the perturbed image to any label that is not the original label. The attack objectives for both are as follows where <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> is the original image, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x^{\prime }}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x^{\prime }}</annotation>
</semantics>
</math></span><img src="./14c1add0558f9ff3f59b73609904dca7d454da15.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.014ex; height:2.343ex;" alt="{\textstyle x^{\prime }}" loading="lazy"></span> is the adversarial image, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle d}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>d</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle d}</annotation>
</semantics>
</math></span><img src="./252135f29da0e9f9e130ff2d53be5df2f7044d99.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.216ex; height:2.176ex;" alt="{\textstyle d}" loading="lazy"></span> is a distance function between images, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle c^{*}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msup>
<mi>c</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>∗<!-- ∗ --></mo>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle c^{*}}</annotation>
</semantics>
</math></span><img src="./547b24590d5655e5935313c20d639cc072cb4602.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.061ex; height:2.176ex;" alt="{\textstyle c^{*}}" loading="lazy"></span> is the target label, and <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle C}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>C</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle C}</annotation>
</semantics>
</math></span><img src="./6dca76d9ff4b48256b6a4a99bcb234b64b2fa72b.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.766ex; height:2.176ex;" alt="{\textstyle C}" loading="lazy"></span> is the model's classification class label function:<sup id="cite_ref-:8_94-0" class="reference"><a href="#cite_note-:8-94"><span class="cite-bracket">[</span>94<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\textbf {Targeted:}}\min _{x^{\prime }}d(x^{\prime },x){\text{ subject to }}C(x^{\prime })=c^{*}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mtext mathvariant="bold">Targeted:</mtext>
</mrow>
</mrow>
<munder>
<mo movablelimits="true" form="prefix">min</mo>
<mrow class="MJX-TeXAtom-ORD">
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
</mrow>
</munder>
<mi>d</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo>,</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mtext> subject to </mtext>
</mrow>
<mi>C</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo stretchy="false">)</mo>
<mo>=</mo>
<msup>
<mi>c</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>∗<!-- ∗ --></mo>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\textbf {Targeted:}}\min _{x^{\prime }}d(x^{\prime },x){\text{ subject to }}C(x^{\prime })=c^{*}}</annotation>
</semantics>
</math></span></span>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\textbf {Untargeted:}}\min _{x^{\prime }}d(x^{\prime },x){\text{ subject to }}C(x^{\prime })\neq C(x)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mtext mathvariant="bold">Untargeted:</mtext>
</mrow>
</mrow>
<munder>
<mo movablelimits="true" form="prefix">min</mo>
<mrow class="MJX-TeXAtom-ORD">
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
</mrow>
</munder>
<mi>d</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo>,</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mtext> subject to </mtext>
</mrow>
<mi>C</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo stretchy="false">)</mo>
<mo>≠<!-- ≠ --></mo>
<mi>C</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\textbf {Untargeted:}}\min _{x^{\prime }}d(x^{\prime },x){\text{ subject to }}C(x^{\prime })\neq C(x)}</annotation>
</semantics>
</math></span></span>
</p><p>To solve this problem, the attack proposes the following boundary function <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle S}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>S</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle S}</annotation>
</semantics>
</math></span><img src="./e10a3c52d186162ec8910ebc0288ce982aef842f.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.499ex; height:2.176ex;" alt="{\textstyle S}" loading="lazy"></span> for both the untargeted and targeted setting:<sup id="cite_ref-:8_94-1" class="reference"><a href="#cite_note-:8-94"><span class="cite-bracket">[</span>94<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle S(x^{\prime }):={\begin{cases}\max _{c\neq C(x)}{F(x^{\prime })_{c}}-F(x^{\prime })_{C(x)},&{\text{(Untargeted)}}\\F(x^{\prime })_{c^{*}}-\max _{c\neq c^{*}}{F(x^{\prime })_{c}},&{\text{(Targeted)}}\end{cases}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>S</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo stretchy="false">)</mo>
<mo>:=</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow>
<mo>{</mo>
<mtable columnalign="left left" rowspacing=".2em" columnspacing="1em" displaystyle="false">
<mtr>
<mtd>
<munder>
<mo movablelimits="true" form="prefix">max</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>c</mi>
<mo>≠<!-- ≠ --></mo>
<mi>C</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
</mrow>
</munder>
<mrow class="MJX-TeXAtom-ORD">
<mi>F</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>c</mi>
</mrow>
</msub>
</mrow>
<mo>−<!-- − --></mo>
<mi>F</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>C</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
</mrow>
</msub>
<mo>,</mo>
</mtd>
<mtd>
<mrow class="MJX-TeXAtom-ORD">
<mtext>(Untargeted)</mtext>
</mrow>
</mtd>
</mtr>
<mtr>
<mtd>
<mi>F</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<msup>
<mi>c</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>∗<!-- ∗ --></mo>
</mrow>
</msup>
</mrow>
</msub>
<mo>−<!-- − --></mo>
<munder>
<mo movablelimits="true" form="prefix">max</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>c</mi>
<mo>≠<!-- ≠ --></mo>
<msup>
<mi>c</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>∗<!-- ∗ --></mo>
</mrow>
</msup>
</mrow>
</munder>
<mrow class="MJX-TeXAtom-ORD">
<mi>F</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>c</mi>
</mrow>
</msub>
</mrow>
<mo>,</mo>
</mtd>
<mtd>
<mrow class="MJX-TeXAtom-ORD">
<mtext>(Targeted)</mtext>
</mrow>
</mtd>
</mtr>
</mtable>
<mo fence="true" stretchy="true" symmetric="true"></mo>
</mrow>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle S(x^{\prime }):={\begin{cases}\max _{c\neq C(x)}{F(x^{\prime })_{c}}-F(x^{\prime })_{C(x)},&{\text{(Untargeted)}}\\F(x^{\prime })_{c^{*}}-\max _{c\neq c^{*}}{F(x^{\prime })_{c}},&{\text{(Targeted)}}\end{cases}}}</annotation>
</semantics>
</math></span></span>
</p><p>This can be further simplified to better visualize the boundary between different potential adversarial examples:<sup id="cite_ref-:8_94-2" class="reference"><a href="#cite_note-:8-94"><span class="cite-bracket">[</span>94<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle S(x^{\prime })>0\iff {\begin{cases}argmax_{c}F(x^{\prime })\neq C(x),&{\text{(Untargeted)}}\\argmax_{c}F(x^{\prime })=c^{*},&{\text{(Targeted)}}\end{cases}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>S</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo stretchy="false">)</mo>
<mo>></mo>
<mn>0</mn>
<mspace width="thickmathspace"></mspace>
<mo stretchy="false">⟺<!-- ⟺ --></mo>
<mspace width="thickmathspace"></mspace>
<mrow class="MJX-TeXAtom-ORD">
<mrow>
<mo>{</mo>
<mtable columnalign="left left" rowspacing=".2em" columnspacing="1em" displaystyle="false">
<mtr>
<mtd>
<mi>a</mi>
<mi>r</mi>
<mi>g</mi>
<mi>m</mi>
<mi>a</mi>
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>c</mi>
</mrow>
</msub>
<mi>F</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo stretchy="false">)</mo>
<mo>≠<!-- ≠ --></mo>
<mi>C</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
<mo>,</mo>
</mtd>
<mtd>
<mrow class="MJX-TeXAtom-ORD">
<mtext>(Untargeted)</mtext>
</mrow>
</mtd>
</mtr>
<mtr>
<mtd>
<mi>a</mi>
<mi>r</mi>
<mi>g</mi>
<mi>m</mi>
<mi>a</mi>
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>c</mi>
</mrow>
</msub>
<mi>F</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo stretchy="false">)</mo>
<mo>=</mo>
<msup>
<mi>c</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>∗<!-- ∗ --></mo>
</mrow>
</msup>
<mo>,</mo>
</mtd>
<mtd>
<mrow class="MJX-TeXAtom-ORD">
<mtext>(Targeted)</mtext>
</mrow>
</mtd>
</mtr>
</mtable>
<mo fence="true" stretchy="true" symmetric="true"></mo>
</mrow>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle S(x^{\prime })>0\iff {\begin{cases}argmax_{c}F(x^{\prime })\neq C(x),&{\text{(Untargeted)}}\\argmax_{c}F(x^{\prime })=c^{*},&{\text{(Targeted)}}\end{cases}}}</annotation>
</semantics>
</math></span></span>
</p><p>With this boundary function, the attack then follows an iterative algorithm to find adversarial examples <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x^{\prime }}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x^{\prime }}</annotation>
</semantics>
</math></span><img src="./14c1add0558f9ff3f59b73609904dca7d454da15.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.014ex; height:2.343ex;" alt="{\textstyle x^{\prime }}" loading="lazy"></span> for a given image <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> that satisfies the attack objectives.
</p>
<ol><li>Initialize <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> to some point where <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle S(x)>0}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>S</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
<mo>></mo>
<mn>0</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle S(x)>0}</annotation>
</semantics>
</math></span><img src="./0104db380c7d6bc1565d62f6b5665fc7758120bb.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:8.899ex; height:2.843ex;" alt="{\textstyle S(x)>0}" loading="lazy"></span></li>
<li>Iterate below
<ol><li>Boundary search</li>
<li>Gradient update
<ul><li>Compute the gradient</li>
<li>Find the step size</li></ul></li></ol></li></ol>
<p>Boundary search uses a modified <a href="Binary_search_algorithm" class="mw-redirect" title="Binary search algorithm">binary search</a> to find the point in which the boundary (as defined by <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle S}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>S</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle S}</annotation>
</semantics>
</math></span><img src="./e10a3c52d186162ec8910ebc0288ce982aef842f.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.499ex; height:2.176ex;" alt="{\textstyle S}" loading="lazy"></span>) intersects with the line between <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> and <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x^{\prime }}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x^{\prime }}</annotation>
</semantics>
</math></span><img src="./14c1add0558f9ff3f59b73609904dca7d454da15.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.014ex; height:2.343ex;" alt="{\textstyle x^{\prime }}" loading="lazy"></span>. The next step involves calculating the gradient for <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span>, and update the original <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> using this gradient and a pre-chosen step size. HopSkipJump authors prove that this iterative algorithm will converge, leading <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> to a point right along the boundary that is very close in distance to the original image.<sup id="cite_ref-:8_94-3" class="reference"><a href="#cite_note-:8-94"><span class="cite-bracket">[</span>94<span class="cite-bracket">]</span></a></sup>
</p><p>However, since HopSkipJump is a proposed black box attack and the iterative algorithm above requires the calculation of a gradient in the second iterative step (which black box attacks do not have access to), the authors propose a solution to gradient calculation that requires only the model's output predictions alone.<sup id="cite_ref-:8_94-4" class="reference"><a href="#cite_note-:8-94"><span class="cite-bracket">[</span>94<span class="cite-bracket">]</span></a></sup> By generating many random vectors in all directions, denoted as <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle u_{b}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msub>
<mi>u</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>b</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle u_{b}}</annotation>
</semantics>
</math></span><img src="./81516298bca201258651070954ea05cec3fbb8d8.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:2.267ex; height:2.009ex;" alt="{\textstyle u_{b}}" loading="lazy"></span>, an approximation of the gradient can be calculated using the average of these random vectors weighted by the sign of the boundary function on the image <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x^{\prime }+\delta _{u_{b}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo>+</mo>
<msub>
<mi>δ<!-- δ --></mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>u</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>b</mi>
</mrow>
</msub>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x^{\prime }+\delta _{u_{b}}}</annotation>
</semantics>
</math></span><img src="./d08082537c42acc67f4c27f708be2ce98f349857.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:7.797ex; height:3.009ex;" alt="{\textstyle x^{\prime }+\delta _{u_{b}}}" loading="lazy"></span>, where <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle \delta _{u_{b}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msub>
<mi>δ<!-- δ --></mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>u</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>b</mi>
</mrow>
</msub>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle \delta _{u_{b}}}</annotation>
</semantics>
</math></span><img src="./1664589028f59270eee06ef05ec0238d5252477b.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:2.942ex; height:3.009ex;" alt="{\textstyle \delta _{u_{b}}}" loading="lazy"></span> is the size of the random vector perturbation:<sup id="cite_ref-:8_94-5" class="reference"><a href="#cite_note-:8-94"><span class="cite-bracket">[</span>94<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \nabla S(x^{\prime },\delta )\approx {\frac {1}{B}}\sum _{b=1}^{B}\phi (x^{\prime }+\delta _{u_{b}})u_{b}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi mathvariant="normal">∇<!-- ∇ --></mi>
<mi>S</mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo>,</mo>
<mi>δ<!-- δ --></mi>
<mo stretchy="false">)</mo>
<mo>≈<!-- ≈ --></mo>
<mrow class="MJX-TeXAtom-ORD">
<mfrac>
<mn>1</mn>
<mi>B</mi>
</mfrac>
</mrow>
<munderover>
<mo>∑<!-- ∑ --></mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>b</mi>
<mo>=</mo>
<mn>1</mn>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>B</mi>
</mrow>
</munderover>
<mi>ϕ<!-- ϕ --></mi>
<mo stretchy="false">(</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi class="MJX-variant" mathvariant="normal">′<!-- ′ --></mi>
</mrow>
</msup>
<mo>+</mo>
<msub>
<mi>δ<!-- δ --></mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>u</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>b</mi>
</mrow>
</msub>
</mrow>
</msub>
<mo stretchy="false">)</mo>
<msub>
<mi>u</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>b</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \nabla S(x^{\prime },\delta )\approx {\frac {1}{B}}\sum _{b=1}^{B}\phi (x^{\prime }+\delta _{u_{b}})u_{b}}</annotation>
</semantics>
</math></span></span>
</p><p>The result of the equation above gives a close approximation of the gradient required in step 2 of the iterative algorithm, completing HopSkipJump as a black box attack.<sup id="cite_ref-95" class="reference"><a href="#cite_note-95"><span class="cite-bracket">[</span>95<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-96" class="reference"><a href="#cite_note-96"><span class="cite-bracket">[</span>96<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:8_94-6" class="reference"><a href="#cite_note-:8-94"><span class="cite-bracket">[</span>94<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading4"><h4 id="White_box_attacks">White box attacks</h4></div>
<p>White box attacks assumes that the adversary has access to model parameters on top of being able to get labels for provided inputs.<sup id="cite_ref-:4_90-1" class="reference"><a href="#cite_note-:4-90"><span class="cite-bracket">[</span>90<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading5"><h5 id="Fast_gradient_sign_method">Fast gradient sign method</h5></div>
<p>One of the first proposed attacks for generating adversarial examples was proposed by Google researchers <a href="Ian_Goodfellow" title="Ian Goodfellow">Ian J. Goodfellow</a>, Jonathon Shlens, and Christian Szegedy.<sup id="cite_ref-:9_97-0" class="reference"><a href="#cite_note-:9-97"><span class="cite-bracket">[</span>97<span class="cite-bracket">]</span></a></sup> The attack was called fast gradient sign method (FGSM), and it consists of adding a linear amount of in-perceivable noise to the image and causing a model to incorrectly classify it. This noise is calculated by multiplying the sign of the gradient with respect to the image we want to perturb by a small constant epsilon. As epsilon increases, the model is more likely to be fooled, but the perturbations become easier to identify as well. Shown below is the equation to generate an adversarial example where <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span> is the original image, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle \epsilon }">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>ϵ<!-- ϵ --></mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle \epsilon }</annotation>
</semantics>
</math></span><img src="./8ab4aaaaf4e9f050f445d2ad1518d9012ef5a24b.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:0.944ex; height:1.676ex;" alt="{\textstyle \epsilon }" loading="lazy"></span> is a very small number, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle \Delta _{x}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<msub>
<mi mathvariant="normal">Δ<!-- Δ --></mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>x</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle \Delta _{x}}</annotation>
</semantics>
</math></span><img src="./c9d10b1d9a462ed9cc492a532dc9bf7b710dc7d9.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:3.108ex; height:2.509ex;" alt="{\textstyle \Delta _{x}}" loading="lazy"></span> is the gradient function, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle J}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>J</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle J}</annotation>
</semantics>
</math></span><img src="./e61cd093040143a8df673790bc7295dea6c191b7.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.471ex; height:2.176ex;" alt="{\textstyle J}" loading="lazy"></span> is the loss function, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle \theta }">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>θ<!-- θ --></mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle \theta }</annotation>
</semantics>
</math></span><img src="./a11744bd71a5eb6efe4f28e12ca57f874d82658c.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.09ex; height:2.176ex;" alt="{\textstyle \theta }" loading="lazy"></span> is the model weights, and <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle y}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>y</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle y}</annotation>
</semantics>
</math></span><img src="./db9936ddb2761b76fa640fb275cb5d1fa4d6fa23.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:1.155ex; height:2.009ex;" alt="{\textstyle y}" loading="lazy"></span> is the true label.<sup id="cite_ref-:11_98-0" class="reference"><a href="#cite_note-:11-98"><span class="cite-bracket">[</span>98<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle adv_{x}=x+\epsilon \cdot sign(\Delta _{x}J(\theta ,x,y))}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>a</mi>
<mi>d</mi>
<msub>
<mi>v</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>x</mi>
</mrow>
</msub>
<mo>=</mo>
<mi>x</mi>
<mo>+</mo>
<mi>ϵ<!-- ϵ --></mi>
<mo>⋅<!-- ⋅ --></mo>
<mi>s</mi>
<mi>i</mi>
<mi>g</mi>
<mi>n</mi>
<mo stretchy="false">(</mo>
<msub>
<mi mathvariant="normal">Δ<!-- Δ --></mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>x</mi>
</mrow>
</msub>
<mi>J</mi>
<mo stretchy="false">(</mo>
<mi>θ<!-- θ --></mi>
<mo>,</mo>
<mi>x</mi>
<mo>,</mo>
<mi>y</mi>
<mo stretchy="false">)</mo>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle adv_{x}=x+\epsilon \cdot sign(\Delta _{x}J(\theta ,x,y))}</annotation>
</semantics>
</math></span></span>
</p><p>One important property of this equation is that the gradient is calculated with respect to the input image since the goal is to generate an image that maximizes the loss for the original image of true label <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle y}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>y</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle y}</annotation>
</semantics>
</math></span><img src="./db9936ddb2761b76fa640fb275cb5d1fa4d6fa23.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:1.155ex; height:2.009ex;" alt="{\textstyle y}" loading="lazy"></span>. In traditional <a href="Gradient_descent" title="Gradient descent">gradient descent</a> (for model training), the gradient is used to update the weights of the model since the goal is to minimize the loss for the model on a ground truth dataset. The Fast Gradient Sign Method was proposed as a fast way to generate adversarial examples to evade the model, based on the hypothesis that neural networks cannot resist even linear amounts of perturbation to the input.<sup id="cite_ref-:10_99-0" class="reference"><a href="#cite_note-:10-99"><span class="cite-bracket">[</span>99<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:11_98-1" class="reference"><a href="#cite_note-:11-98"><span class="cite-bracket">[</span>98<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:9_97-1" class="reference"><a href="#cite_note-:9-97"><span class="cite-bracket">[</span>97<span class="cite-bracket">]</span></a></sup> FGSM has shown to be effective in adversarial attacks for image classification and skeletal action recognition.<sup id="cite_ref-coronafigueroaa23unaligned_100-0" class="reference"><a href="#cite_note-coronafigueroaa23unaligned-100"><span class="cite-bracket">[</span>100<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading5"><h5 id="Carlini_&_Wagner_(C&W)">Carlini & Wagner (C&W)</h5></div>
<p>In an effort to analyze existing adversarial attacks and defenses, researchers at the University of California, Berkeley, <a href="Nicholas_Carlini" title="Nicholas Carlini">Nicholas Carlini</a> and <a href="David_A._Wagner" title="David A. Wagner">David Wagner</a> in 2016 propose a faster and more robust method to generate adversarial examples.<sup id="cite_ref-:5_101-0" class="reference"><a href="#cite_note-:5-101"><span class="cite-bracket">[</span>101<span class="cite-bracket">]</span></a></sup>
</p><p>The attack proposed by Carlini and Wagner begins with trying to solve a difficult non-linear optimization equation:<sup id="cite_ref-:12_66-1" class="reference"><a href="#cite_note-:12-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \min(||\delta ||_{p}){\text{ subject to }}C(x+\delta )=t,x+\delta \in [0,1]^{n}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mo movablelimits="true" form="prefix">min</mo>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mi>δ<!-- δ --></mi>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>p</mi>
</mrow>
</msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mtext> subject to </mtext>
</mrow>
<mi>C</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo>+</mo>
<mi>δ<!-- δ --></mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mi>t</mi>
<mo>,</mo>
<mi>x</mi>
<mo>+</mo>
<mi>δ<!-- δ --></mi>
<mo>∈<!-- ∈ --></mo>
<mo stretchy="false">[</mo>
<mn>0</mn>
<mo>,</mo>
<mn>1</mn>
<msup>
<mo stretchy="false">]</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \min(||\delta ||_{p}){\text{ subject to }}C(x+\delta )=t,x+\delta \in [0,1]^{n}}</annotation>
</semantics>
</math></span></span>
</p><p>Here the objective is to minimize the noise (<span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle \delta }">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>δ<!-- δ --></mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle \delta }</annotation>
</semantics>
</math></span><img src="./ec578ebbf0a029f13dca70687f072742277a87ea.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.049ex; height:2.343ex;" alt="{\textstyle \delta }" loading="lazy"></span>), added to the original input <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span>, such that the machine learning algorithm (<span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle C}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>C</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle C}</annotation>
</semantics>
</math></span><img src="./6dca76d9ff4b48256b6a4a99bcb234b64b2fa72b.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.766ex; height:2.176ex;" alt="{\textstyle C}" loading="lazy"></span>) predicts the original input with delta (or <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x+\delta }">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
<mo>+</mo>
<mi>δ<!-- δ --></mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x+\delta }</annotation>
</semantics>
</math></span><img src="./ffcd3c1a282a339ef0636a853da0e6bcb3f797f7.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.505ex; width:5.219ex; height:2.509ex;" alt="{\textstyle x+\delta }" loading="lazy"></span>) as some other class <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle t}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>t</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle t}</annotation>
</semantics>
</math></span><img src="./b2bc926f90178739fccd01a96c6fa778ab3535d6.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:0.84ex; height:2.009ex;" alt="{\textstyle t}" loading="lazy"></span>. However instead of directly the above equation, Carlini and Wagner propose using a new function <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle f}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>f</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle f}</annotation>
</semantics>
</math></span><img src="./e1b77076edca76caf3331d0551d1645b8f678283.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:1.279ex; height:2.509ex;" alt="{\textstyle f}" loading="lazy"></span> such that:<sup id="cite_ref-:12_66-2" class="reference"><a href="#cite_note-:12-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle C(x+\delta )=t\iff f(x+\delta )\leq 0}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>C</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo>+</mo>
<mi>δ<!-- δ --></mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mi>t</mi>
<mspace width="thickmathspace"></mspace>
<mo stretchy="false">⟺<!-- ⟺ --></mo>
<mspace width="thickmathspace"></mspace>
<mi>f</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo>+</mo>
<mi>δ<!-- δ --></mi>
<mo stretchy="false">)</mo>
<mo>≤<!-- ≤ --></mo>
<mn>0</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle C(x+\delta )=t\iff f(x+\delta )\leq 0}</annotation>
</semantics>
</math></span></span>
</p><p>This condenses the first equation to the problem below:<sup id="cite_ref-:12_66-3" class="reference"><a href="#cite_note-:12-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \min(||\delta ||_{p}){\text{ subject to }}f(x+\delta )\leq 0,x+\delta \in [0,1]^{n}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mo movablelimits="true" form="prefix">min</mo>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mi>δ<!-- δ --></mi>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>p</mi>
</mrow>
</msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mtext> subject to </mtext>
</mrow>
<mi>f</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo>+</mo>
<mi>δ<!-- δ --></mi>
<mo stretchy="false">)</mo>
<mo>≤<!-- ≤ --></mo>
<mn>0</mn>
<mo>,</mo>
<mi>x</mi>
<mo>+</mo>
<mi>δ<!-- δ --></mi>
<mo>∈<!-- ∈ --></mo>
<mo stretchy="false">[</mo>
<mn>0</mn>
<mo>,</mo>
<mn>1</mn>
<msup>
<mo stretchy="false">]</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \min(||\delta ||_{p}){\text{ subject to }}f(x+\delta )\leq 0,x+\delta \in [0,1]^{n}}</annotation>
</semantics>
</math></span></span>
</p><p>and even more to the equation below:<sup id="cite_ref-:12_66-4" class="reference"><a href="#cite_note-:12-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \min(||\delta ||_{p}+c\cdot f(x+\delta )),x+\delta \in [0,1]^{n}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mo movablelimits="true" form="prefix">min</mo>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mi>δ<!-- δ --></mi>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">|</mo>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>p</mi>
</mrow>
</msub>
<mo>+</mo>
<mi>c</mi>
<mo>⋅<!-- ⋅ --></mo>
<mi>f</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo>+</mo>
<mi>δ<!-- δ --></mi>
<mo stretchy="false">)</mo>
<mo stretchy="false">)</mo>
<mo>,</mo>
<mi>x</mi>
<mo>+</mo>
<mi>δ<!-- δ --></mi>
<mo>∈<!-- ∈ --></mo>
<mo stretchy="false">[</mo>
<mn>0</mn>
<mo>,</mo>
<mn>1</mn>
<msup>
<mo stretchy="false">]</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \min(||\delta ||_{p}+c\cdot f(x+\delta )),x+\delta \in [0,1]^{n}}</annotation>
</semantics>
</math></span></span>
</p><p>Carlini and Wagner then propose the use of the below function in place of <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle f}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>f</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle f}</annotation>
</semantics>
</math></span><img src="./e1b77076edca76caf3331d0551d1645b8f678283.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:1.279ex; height:2.509ex;" alt="{\textstyle f}" loading="lazy"></span> using <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle Z}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>Z</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle Z}</annotation>
</semantics>
</math></span><img src="./d442d6fe240625e70b574360ee971066244df646.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.68ex; height:2.176ex;" alt="{\textstyle Z}" loading="lazy"></span>, a function that determines class probabilities for given input <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\textstyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\textstyle x}</annotation>
</semantics>
</math></span><img src="./d951e0f3b54b6a3d73bb9a0a005749046cbce781.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\textstyle x}" loading="lazy"></span>. When substituted in, this equation can be thought of as finding a target class that is more confident than the next likeliest class by some constant amount:<sup id="cite_ref-:12_66-5" class="reference"><a href="#cite_note-:12-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup>
</p><p><span class="mwe-math-element mwe-math-element-block"><span class="mwe-math-mathml-display mwe-math-mathml-a11y" style="display: none;"><math display="block" xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle f(x)=([\max _{i\neq t}Z(x)_{i}]-Z(x)_{t})^{+}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>f</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mo stretchy="false">(</mo>
<mo stretchy="false">[</mo>
<munder>
<mo movablelimits="true" form="prefix">max</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>≠<!-- ≠ --></mo>
<mi>t</mi>
</mrow>
</munder>
<mi>Z</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
</mrow>
</msub>
<mo stretchy="false">]</mo>
<mo>−<!-- − --></mo>
<mi>Z</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>t</mi>
</mrow>
</msub>
<msup>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mo>+</mo>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle f(x)=([\max _{i\neq t}Z(x)_{i}]-Z(x)_{t})^{+}}</annotation>
</semantics>
</math></span></span>
</p><p>When solved using gradient descent, this equation is able to produce stronger adversarial examples when compared to fast gradient sign method that is also able to bypass defensive distillation, a defense that was once proposed to be effective against adversarial examples.<sup id="cite_ref-102" class="reference"><a href="#cite_note-102"><span class="cite-bracket">[</span>102<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-103" class="reference"><a href="#cite_note-103"><span class="cite-bracket">[</span>103<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:5_101-1" class="reference"><a href="#cite_note-:5-101"><span class="cite-bracket">[</span>101<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:12_66-6" class="reference"><a href="#cite_note-:12-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Defenses">Defenses</h2></div>
<p>Researchers have proposed a multi-step approach to protecting machine learning.<sup id="cite_ref-:02_11-1" class="reference"><a href="#cite_note-:02-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</p>
<ul><li>Threat modeling – Formalize the attackers goals and capabilities with respect to the target system.</li>
<li>Attack simulation – Formalize the optimization problem the attacker tries to solve according to possible attack strategies.</li>
<li>Attack impact evaluation</li>
<li>Countermeasure design</li>
<li>Noise detection (For evasion based attack)<sup id="cite_ref-104" class="reference"><a href="#cite_note-104"><span class="cite-bracket">[</span>104<span class="cite-bracket">]</span></a></sup></li>
<li>Information laundering – Alter the information received by adversaries (for model stealing attacks)<sup id="cite_ref-:12_66-7" class="reference"><a href="#cite_note-:12-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading3"><h3 id="Mechanisms">Mechanisms</h3></div>
<p>A number of defense mechanisms against evasion, poisoning, and privacy attacks have been proposed, including:
</p>
<ul><li>Secure learning algorithms<sup id="cite_ref-Adversarial_Machine_Learning_18A2_20-1" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_18A2-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_22A2_105-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_22A2-105"><span class="cite-bracket">[</span>105<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_45A2_106-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_45A2-106"><span class="cite-bracket">[</span>106<span class="cite-bracket">]</span></a></sup></li>
<li>Byzantine-resilient algorithms<sup id="cite_ref-:14_57-1" class="reference"><a href="#cite_note-:14-57"><span class="cite-bracket">[</span>57<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:13_5-2" class="reference"><a href="#cite_note-:13-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup></li>
<li>Multiple classifier systems<sup id="cite_ref-BiggioFumera20102_19-1" class="reference"><a href="#cite_note-BiggioFumera20102-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_10A2_107-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_10A2-107"><span class="cite-bracket">[</span>107<span class="cite-bracket">]</span></a></sup></li>
<li>AI-written algorithms.<sup id="cite_ref-nature_why2_35-1" class="reference"><a href="#cite_note-nature_why2-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup></li>
<li>AIs that explore the training environment; for example, in image recognition, actively navigating a 3D environment rather than passively scanning a fixed set of 2D images.<sup id="cite_ref-nature_why2_35-2" class="reference"><a href="#cite_note-nature_why2-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup></li>
<li>Privacy-preserving learning<sup id="cite_ref-Adversarial_Machine_Learning_5A2_44-4" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_5A2-44"><span class="cite-bracket">[</span>44<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Adversarial_Machine_Learning_41A2_108-0" class="reference"><a href="#cite_note-Adversarial_Machine_Learning_41A2-108"><span class="cite-bracket">[</span>108<span class="cite-bracket">]</span></a></sup></li>
<li>Ladder algorithm for <a href="Kaggle" title="Kaggle">Kaggle</a>-style competitions</li>
<li>Game theoretic models<sup id="cite_ref-feature_select2_109-0" class="reference"><a href="#cite_note-feature_select2-109"><span class="cite-bracket">[</span>109<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-110" class="reference"><a href="#cite_note-110"><span class="cite-bracket">[</span>110<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-111" class="reference"><a href="#cite_note-111"><span class="cite-bracket">[</span>111<span class="cite-bracket">]</span></a></sup></li>
<li>Sanitizing training data</li>
<li>Adversarial training<sup id="cite_ref-Explaining_and_Harnessing_Adversari2_85-1" class="reference"><a href="#cite_note-Explaining_and_Harnessing_Adversari2-85"><span class="cite-bracket">[</span>85<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:0_22-1" class="reference"><a href="#cite_note-:0-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup></li>
<li>Backdoor detection algorithms<sup id="cite_ref-112" class="reference"><a href="#cite_note-112"><span class="cite-bracket">[</span>112<span class="cite-bracket">]</span></a></sup></li>
<li>Gradient masking/obfuscation techniques: to prevent the adversary exploiting the gradient in white-box attacks. This family of defenses is deemed unreliable as these models are still vulnerable to black-box attacks or can be circumvented in other ways.<sup id="cite_ref-113" class="reference"><a href="#cite_note-113"><span class="cite-bracket">[</span>113<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Ensemble_learning" title="Ensemble learning">Ensembles</a> of models have been proposed in literature, which have shown to be ineffective against evasion attacks<sup id="cite_ref-114" class="reference"><a href="#cite_note-114"><span class="cite-bracket">[</span>114<span class="cite-bracket">]</span></a></sup> but effective against data poisoning attacks.<sup id="cite_ref-115" class="reference"><a href="#cite_note-115"><span class="cite-bracket">[</span>115<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Pattern_recognition" title="Pattern recognition">Pattern recognition</a></li>
<li><a href="Fawkes_(image_cloaking_software)" class="mw-redirect" title="Fawkes (image cloaking software)">Fawkes (image cloaking software)</a></li>
<li><a href="Generative_adversarial_network" title="Generative adversarial network">Generative adversarial network</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFKianpourWen2020" class="citation book cs1">Kianpour, Mazaher; Wen, Shao-Fang (2020). "Timing Attacks on Machine Learning: State of the Art". <i>Intelligent Systems and Applications</i>. Advances in Intelligent Systems and Computing. Vol. 1037. pp. <span class="nowrap">111–</span>125. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-030-29516-5_10">10.1007/978-3-030-29516-5_10</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-3-030-29515-8</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:201705926">201705926</a>.</cite></span>
</li>
<li id="cite_note-:1-2"><span class="mw-cite-backlink">^ <a href="#cite_ref-:1_2-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:1_2-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFSiva_KumarNyströmLambertMarshall2020" class="citation book cs1">Siva Kumar, Ram Shankar; Nyström, Magnus; Lambert, John; Marshall, Andrew; Goertzel, Mario; Comissoneru, Andi; Swann, Matt; Xia, Sharon (May 2020). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/9283867">"Adversarial Machine Learning-Industry Perspectives"</a>. <i>2020 IEEE Security and Privacy Workshops (SPW)</i>. pp. <span class="nowrap">69–</span>75. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSPW50608.2020.00028">10.1109/SPW50608.2020.00028</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-7281-9346-5</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:229357721">229357721</a>.</cite></span>
</li>
<li id="cite_note-GoodfellowMcDaniel20182-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-GoodfellowMcDaniel20182_3-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFGoodfellowMcDanielPapernot2018" class="citation journal cs1">Goodfellow, Ian; McDaniel, Patrick; Papernot, Nicolas (25 June 2018). <a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F3134599">"Making machine learning robust against adversarial inputs"</a>. <i>Communications of the ACM</i>. <b>61</b> (7): <span class="nowrap">56–</span>66. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F3134599">10.1145/3134599</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0001-0782">0001-0782</a>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite id="CITEREFGeipingFowlHuangCzaja2020" class="citation conference cs1">Geiping, Jonas; Fowl, Liam H.; Huang, W. Ronny; Czaja, Wojciech; Taylor, Gavin; Moeller, Michael; Goldstein, Tom (2020-09-28). <a rel="nofollow" class="external text" href="https://openreview.net/forum?id=01olnfLIbD"><i>Witches' Brew: Industrial Scale Data Poisoning via Gradient Matching</i></a>. International Conference on Learning Representations 2021 (Poster).</cite></span>
</li>
<li id="cite_note-:13-5"><span class="mw-cite-backlink">^ <a href="#cite_ref-:13_5-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:13_5-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:13_5-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFEl-MhamdiFarhadkhaniGuerraouiGuirguis2021" class="citation journal cs1">El-Mhamdi, El Mahdi; Farhadkhani, Sadegh; Guerraoui, Rachid; Guirguis, Arsany; Hoang, Lê-Nguyên; Rouault, Sébastien (2021-12-06). <a rel="nofollow" class="external text" href="https://proceedings.neurips.cc/paper/2021/hash/d2cd33e9c0236a8c2d8bd3fa91ad3acf-Abstract.html">"Collaborative Learning in the Jungle (Decentralized, Byzantine, Heterogeneous, Asynchronous and Nonconvex Learning)"</a>. <i>Advances in Neural Information Processing Systems</i>. <b>34</b>. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2008.00742">2008.00742</a></span>.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite id="CITEREFTramèrZhangJuelsReiter2016" class="citation conference cs1">Tramèr, Florian; Zhang, Fan; Juels, Ari; Reiter, Michael K.; Ristenpart, Thomas (2016). <a rel="nofollow" class="external text" href="https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/tramer"><i>Stealing Machine Learning Models via Prediction {APIs}</i></a>. 25th USENIX Security Symposium. pp. <span class="nowrap">601–</span>618. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-931971-32-4</bdi>.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://blog.jgc.org/2023/07/how-to-beat-adaptivebayesian-spam.html">"How to beat an adaptive/Bayesian spam filter (2004)"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-07-05</span></span>.</cite></span>
</li>
<li id="cite_note-Poisoning_Attacks_against_Support_V-8"><span class="mw-cite-backlink">^ <a href="#cite_ref-Poisoning_Attacks_against_Support_V_8-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Poisoning_Attacks_against_Support_V_8-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBiggioNelsonLaskov2013" class="citation arxiv cs1">Biggio, Battista; Nelson, Blaine; Laskov, Pavel (2013-03-25). "Poisoning Attacks against Support Vector Machines". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1206.6389">1206.6389</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.LG">cs.LG</a>].</cite></span>
</li>
<li id="cite_note-Springer-9"><span class="mw-cite-backlink">^ <a href="#cite_ref-Springer_9-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Springer_9-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-Springer_9-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBiggioCoronaMaiorcaNelson2013" class="citation book cs1">Biggio, Battista; Corona, Igino; Maiorca, Davide; Nelson, Blaine; Srndic, Nedim; Laskov, Pavel; Giacinto, Giorgio; Roli, Fabio (2013). "Evasion Attacks against Machine Learning at Test Time". <i>Advanced Information Systems Engineering</i>. Lecture Notes in Computer Science. Vol. 7908. Springer. pp. <span class="nowrap">387–</span>402. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1708.06131">1708.06131</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-642-40994-3_25">10.1007/978-3-642-40994-3_25</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-3-642-38708-1</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:18716873">18716873</a>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite id="CITEREFSzegedyZarembaSutskeverBruna2014" class="citation arxiv cs1">Szegedy, Christian; Zaremba, Wojciech; Sutskever, Ilya; Bruna, Joan; Erhan, Dumitru; Goodfellow, Ian; Fergus, Rob (2014-02-19). "Intriguing properties of neural networks". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1312.6199">1312.6199</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CV">cs.CV</a>].</cite></span>
</li>
<li id="cite_note-:02-11"><span class="mw-cite-backlink">^ <a href="#cite_ref-:02_11-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:02_11-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBiggioRoli2018" class="citation journal cs1">Biggio, Battista; Roli, Fabio (December 2018). "Wild patterns: Ten years after the rise of adversarial machine learning". <i>Pattern Recognition</i>. <b>84</b>: <span class="nowrap">317–</span>331. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1712.03141">1712.03141</a></span>. <a href="Bibcode_(identifier)" class="mw-redirect" title="Bibcode (identifier)">Bibcode</a>:<a rel="nofollow" class="external text" href="https://ui.adsabs.harvard.edu/abs/2018PatRe..84..317B">2018PatRe..84..317B</a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1016%2Fj.patcog.2018.07.023">10.1016/j.patcog.2018.07.023</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:207324435">207324435</a>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite id="CITEREFKurakinGoodfellowBengio2016" class="citation arxiv cs1">Kurakin, Alexey; Goodfellow, Ian; Bengio, Samy (2016). "Adversarial examples in the physical world". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1607.02533">1607.02533</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CV">cs.CV</a>].</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text">Gupta, Kishor Datta, Dipankar Dasgupta, and Zahid Akhtar. "Applicability issues of Evasion-Based Adversarial Attacks and Mitigation Techniques." 2020 IEEE Symposium Series on Computational Intelligence (SSCI). 2020.</span>
</li>
<li id="cite_note-LimTaeihagh20192-14"><span class="mw-cite-backlink">^ <a href="#cite_ref-LimTaeihagh20192_14-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-LimTaeihagh20192_14-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFLimTaeihagh2019" class="citation journal cs1">Lim, Hazel Si Min; Taeihagh, Araz (2019). <a rel="nofollow" class="external text" href="https://doi.org/10.3390%2Fsu11205791">"Algorithmic Decision-Making in AVs: Understanding Ethical and Technical Concerns for Smart Cities"</a>. <i>Sustainability</i>. <b>11</b> (20): 5791. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1910.13122">1910.13122</a></span>. <a href="Bibcode_(identifier)" class="mw-redirect" title="Bibcode (identifier)">Bibcode</a>:<a rel="nofollow" class="external text" href="https://ui.adsabs.harvard.edu/abs/2019arXiv191013122L">2019arXiv191013122L</a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.3390%2Fsu11205791">10.3390/su11205791</a></span>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:204951009">204951009</a>.</cite></span>
</li>
<li id="cite_note-:2-15"><span class="mw-cite-backlink">^ <a href="#cite_ref-:2_15-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:2_15-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://syncedreview.com/2019/11/21/google-brains-nicholas-frosst-on-adversarial-examples-and-emotional-responses/">"Google Brain's Nicholas Frosst on Adversarial Examples and Emotional Responses"</a>. <i>Synced</i>. 2019-11-21<span class="reference-accessdate">. Retrieved <span class="nowrap">2021-10-23</span></span>.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://ai.google/responsibilities/responsible-ai-practices/">"Responsible AI practices"</a>. <i>Google AI</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-10-23</span></span>.</cite></span>
</li>
<li id="cite_note-:3-17"><span class="mw-cite-backlink">^ <a href="#cite_ref-:3_17-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:3_17-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:3_17-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation cs2"><a rel="nofollow" class="external text" href="https://github.com/Trusted-AI/adversarial-robustness-toolbox"><i>Adversarial Robustness Toolbox (ART) v1.8</i></a>, Trusted-AI, 2021-10-23<span class="reference-accessdate">, retrieved <span class="nowrap">2021-10-23</span></span></cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite id="CITEREFamarshal" class="citation web cs1">amarshal. <a rel="nofollow" class="external text" href="https://docs.microsoft.com/en-us/security/engineering/failure-modes-in-machine-learning">"Failure Modes in Machine Learning - Security documentation"</a>. <i>docs.microsoft.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-10-23</span></span>.</cite></span>
</li>
<li id="cite_note-BiggioFumera20102-19"><span class="mw-cite-backlink">^ <a href="#cite_ref-BiggioFumera20102_19-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-BiggioFumera20102_19-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBiggioFumeraRoli2010" class="citation journal cs1">Biggio, Battista; Fumera, Giorgio; Roli, Fabio (2010). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20230119094021/http://pralab.diee.unica.it/en/node/671">"Multiple classifier systems for robust classifier design in adversarial environments"</a>. <i>International Journal of Machine Learning and Cybernetics</i>. <b>1</b> (<span class="nowrap">1–</span>4): <span class="nowrap">27–</span>41. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2Fs13042-010-0007-7">10.1007/s13042-010-0007-7</a>. <a href="Hdl_(identifier)" class="mw-redirect" title="Hdl (identifier)">hdl</a>:<a rel="nofollow" class="external text" href="https://hdl.handle.net/11567%2F1087824">11567/1087824</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1868-8071">1868-8071</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:8729381">8729381</a>. Archived from <span class="id-lock-subscription" title="Paid subscription required"><a rel="nofollow" class="external text" href="http://pralab.diee.unica.it/en/node/671">the original</a></span> on 2023-01-19<span class="reference-accessdate">. Retrieved <span class="nowrap">2015-01-14</span></span>.</cite></span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_18A2-20"><span class="mw-cite-backlink">^ <a href="#cite_ref-Adversarial_Machine_Learning_18A2_20-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Adversarial_Machine_Learning_18A2_20-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBrücknerKanzowScheffer2012" class="citation journal cs1">Brückner, Michael; Kanzow, Christian; Scheffer, Tobias (2012). <a rel="nofollow" class="external text" href="http://www.jmlr.org/papers/volume13/brueckner12a/brueckner12a.pdf">"Static Prediction Games for Adversarial Learning Problems"</a> <span class="cs1-format">(PDF)</span>. <i>Journal of Machine Learning Research</i>. <b>13</b> (Sep): <span class="nowrap">2617–</span>2654. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1533-7928">1533-7928</a>.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite id="CITEREFApruzzeseAndreoliniFerrettiMarchetti2021" class="citation journal cs1">Apruzzese, Giovanni; Andreolini, Mauro; Ferretti, Luca; Marchetti, Mirco; Colajanni, Michele (2021-06-03). "Modeling Realistic Adversarial Attacks against Network Intrusion Detection Systems". <i>Digital Threats: Research and Practice</i>. <b>3</b> (3): <span class="nowrap">1–</span>19. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2106.09380">2106.09380</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F3469659">10.1145/3469659</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/2692-1626">2692-1626</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:235458519">235458519</a>.</cite></span>
</li>
<li id="cite_note-:0-22"><span class="mw-cite-backlink">^ <a href="#cite_ref-:0_22-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:0_22-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFVitorinoOliveiraPraça2022" class="citation journal cs1">Vitorino, João; Oliveira, Nuno; Praça, Isabel (March 2022). <a rel="nofollow" class="external text" href="https://doi.org/10.3390%2Ffi14040108">"Adaptative Perturbation Patterns: Realistic Adversarial Learning for Robust Intrusion Detection"</a>. <i>Future Internet</i>. <b>14</b> (4): 108. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.3390%2Ffi14040108">10.3390/fi14040108</a></span>. <a href="Hdl_(identifier)" class="mw-redirect" title="Hdl (identifier)">hdl</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://hdl.handle.net/10400.22%2F21851">10400.22/21851</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1999-5903">1999-5903</a>.</cite></span>
</li>
<li id="cite_note-RodriguesLing20092-23"><span class="mw-cite-backlink">^ <a href="#cite_ref-RodriguesLing20092_23-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-RodriguesLing20092_23-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFRodriguesLingGovindaraju2009" class="citation journal cs1">Rodrigues, Ricardo N.; Ling, Lee Luan; Govindaraju, Venu (1 June 2009). <a rel="nofollow" class="external text" href="http://cubs.cedar.buffalo.edu/images/pdf/pub/robustness-of-multimodal-biometric-fusion-methods-against-spoof-attacks.pdf">"Robustness of multimodal biometric fusion methods against spoof attacks"</a> <span class="cs1-format">(PDF)</span>. <i>Journal of Visual Languages & Computing</i>. <b>20</b> (3): <span class="nowrap">169–</span>179. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1016%2Fj.jvlc.2009.01.010">10.1016/j.jvlc.2009.01.010</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1045-926X">1045-926X</a>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite id="CITEREFSuVargasSakurai2019" class="citation journal cs1">Su, Jiawei; Vargas, Danilo Vasconcellos; Sakurai, Kouichi (October 2019). "One Pixel Attack for Fooling Deep Neural Networks". <i>IEEE Transactions on Evolutionary Computation</i>. <b>23</b> (5): <span class="nowrap">828–</span>841. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1710.08864">1710.08864</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FTEVC.2019.2890858">10.1109/TEVC.2019.2890858</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1941-0026">1941-0026</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:2698863">2698863</a>.</cite></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://www.bbc.com/news/technology-41845878">"Single pixel change fools AI programs"</a>. <i>BBC News</i>. 3 November 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">12 February</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><cite id="CITEREFAthalyeEngstromIlyasKwok2017" class="citation arxiv cs1">Athalye, Anish; Engstrom, Logan; Ilyas, Andrew; Kwok, Kevin (2017). "Synthesizing Robust Adversarial Examples". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1707.07397">1707.07397</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CV">cs.CV</a>].</cite></span>
</li>
<li id="cite_note-27"><span class="mw-cite-backlink"><b><a href="#cite_ref-27">^</a></b></span> <span class="reference-text"><cite class="citation magazine cs1"><a rel="nofollow" class="external text" href="https://www.wired.com/story/ai-has-a-hallucination-problem-thats-proving-tough-to-fix/">"AI Has a Hallucination Problem That's Proving Tough to Fix"</a>. <i>WIRED</i>. 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">10 March</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite id="CITEREFZhouFirestone2019" class="citation journal cs1">Zhou, Zhenglong; Firestone, Chaz (2019). <a rel="nofollow" class="external text" href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6430776">"Humans can decipher adversarial images"</a>. <i>Nature Communications</i>. <b>10</b> (1): 1334. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1809.04120">1809.04120</a></span>. <a href="Bibcode_(identifier)" class="mw-redirect" title="Bibcode (identifier)">Bibcode</a>:<a rel="nofollow" class="external text" href="https://ui.adsabs.harvard.edu/abs/2019NatCo..10.1334Z">2019NatCo..10.1334Z</a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1038%2Fs41467-019-08931-6">10.1038/s41467-019-08931-6</a></span>. <a href="PMC_(identifier)" class="mw-redirect" title="PMC (identifier)">PMC</a> <span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6430776">6430776</a></span>. <a href="PMID_(identifier)" class="mw-redirect" title="PMID (identifier)">PMID</a> <a rel="nofollow" class="external text" href="https://pubmed.ncbi.nlm.nih.gov/30902973">30902973</a>.</cite></span>
</li>
<li id="cite_note-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-29">^</a></b></span> <span class="reference-text"><cite id="CITEREFAckerman2017" class="citation web cs1">Ackerman, Evan (2017-08-04). <a rel="nofollow" class="external text" href="https://spectrum.ieee.org/slight-street-sign-modifications-can-fool-machine-learning-algorithms">"Slight Street Sign Modifications Can Completely Fool Machine Learning Algorithms"</a>. <i>IEEE Spectrum: Technology, Engineering, and Science News</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2019-07-15</span></span>.</cite></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><cite id="CITEREFEdwards2023" class="citation web cs1">Edwards, Benj (2023-10-25). <a rel="nofollow" class="external text" href="https://arstechnica.com/information-technology/2023/10/university-of-chicago-researchers-seek-to-poison-ai-art-generators-with-nightshade/">"University of Chicago researchers seek to "poison" AI art generators with Nightshade"</a>. <i>Ars Technica</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2025-06-25</span></span>.</cite></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text"><cite id="CITEREFShanDingPassanantiWu2024" class="citation cs2">Shan, Shawn; Ding, Wenxin; Passananti, Josephine; Wu, Stanley; Zheng, Haitao; Zhao, Ben Y. (2024-04-29), <a rel="nofollow" class="external text" href="http://arxiv.org/abs/2310.13828"><i>Nightshade: Prompt-Specific Poisoning Attacks on Text-to-Image Generative Models</i></a>, arXiv, <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.48550%2FarXiv.2310.13828">10.48550/arXiv.2310.13828</a>, arXiv:2310.13828<span class="reference-accessdate">, retrieved <span class="nowrap">2025-06-25</span></span></cite></span>
</li>
<li id="cite_note-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-32">^</a></b></span> <span class="reference-text"><cite class="citation magazine cs1"><a rel="nofollow" class="external text" href="https://www.wired.com/story/tesla-speed-up-adversarial-example-mgm-breach-ransomware/">"A Tiny Piece of Tape Tricked Teslas Into Speeding Up 50 MPH"</a>. <i>Wired</i>. 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">11 March</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-33">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://securingtomorrow.mcafee.com/blogs/other-blogs/mcafee-labs/model-hacking-adas-to-pave-safer-roads-for-autonomous-vehicles">"Model Hacking ADAS to Pave Safer Roads for Autonomous Vehicles"</a>. <i>McAfee Blogs</i>. 2020-02-19<span class="reference-accessdate">. Retrieved <span class="nowrap">2020-03-11</span></span>.</cite></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text"><cite id="CITEREFSeabrook2020" class="citation magazine cs1">Seabrook, John (2020). <a rel="nofollow" class="external text" href="https://www.newyorker.com/magazine/2020/03/16/dressing-for-the-surveillance-age">"Dressing for the Surveillance Age"</a>. <i>The New Yorker</i><span class="reference-accessdate">. Retrieved <span class="nowrap">5 April</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-nature_why2-35"><span class="mw-cite-backlink">^ <a href="#cite_ref-nature_why2_35-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-nature_why2_35-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-nature_why2_35-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFHeaven2019" class="citation journal cs1">Heaven, Douglas (October 2019). "Why deep-learning AIs are so easy to fool". <i>Nature</i>. <b>574</b> (7777): <span class="nowrap">163–</span>166. <a href="Bibcode_(identifier)" class="mw-redirect" title="Bibcode (identifier)">Bibcode</a>:<a rel="nofollow" class="external text" href="https://ui.adsabs.harvard.edu/abs/2019Natur.574..163H">2019Natur.574..163H</a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1038%2Fd41586-019-03013-5">10.1038/d41586-019-03013-5</a>. <a href="PMID_(identifier)" class="mw-redirect" title="PMID (identifier)">PMID</a> <a rel="nofollow" class="external text" href="https://pubmed.ncbi.nlm.nih.gov/31597977">31597977</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:203928744">203928744</a>.</cite></span>
</li>
<li id="cite_note-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-36">^</a></b></span> <span class="reference-text"><cite id="CITEREFHutson2019" class="citation journal cs1">Hutson, Matthew (10 May 2019). "AI can now defend itself against malicious messages hidden in speech". <i>Nature</i>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1038%2Fd41586-019-01510-1">10.1038/d41586-019-01510-1</a>. <a href="PMID_(identifier)" class="mw-redirect" title="PMID (identifier)">PMID</a> <a rel="nofollow" class="external text" href="https://pubmed.ncbi.nlm.nih.gov/32385365">32385365</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:189666088">189666088</a>.</cite></span>
</li>
<li id="cite_note-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-37">^</a></b></span> <span class="reference-text"><cite id="CITEREFLeporiFirestone2020" class="citation arxiv cs1">Lepori, Michael A; Firestone, Chaz (2020-03-27). "Can you hear me now? Sensitive comparisons of human and machine perception". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2003.12362">2003.12362</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/eess.AS">eess.AS</a>].</cite></span>
</li>
<li id="cite_note-38"><span class="mw-cite-backlink"><b><a href="#cite_ref-38">^</a></b></span> <span class="reference-text"><cite id="CITEREFVadilloSantana2020" class="citation arxiv cs1">Vadillo, Jon; Santana, Roberto (2020-01-23). "On the human evaluation of audio adversarial examples". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2001.08444">2001.08444</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/eess.AS">eess.AS</a>].</cite></span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_42A2-39"><span class="mw-cite-backlink"><b><a href="#cite_ref-Adversarial_Machine_Learning_42A2_39-0">^</a></b></span> <span class="reference-text">D. B. Skillicorn. "Adversarial knowledge discovery". IEEE Intelligent Systems, 24:54–61, 2009.</span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_46A2-40"><span class="mw-cite-backlink">^ <a href="#cite_ref-Adversarial_Machine_Learning_46A2_40-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Adversarial_Machine_Learning_46A2_40-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text">B. Biggio, G. Fumera, and F. Roli. "<a rel="nofollow" class="external text" href="http://pralab.diee.unica.it/en/node/1103">Pattern recognition systems under attack: Design issues and research challenges</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20220520211435/https://pralab.diee.unica.it/en/node/1103">Archived</a> 2022-05-20 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a>". Int'l J. Patt. Recogn. Artif. Intell., 28(7):1460002, 2014.</span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_22-41"><span class="mw-cite-backlink">^ <a href="#cite_ref-Adversarial_Machine_Learning_22_41-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Adversarial_Machine_Learning_22_41-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBarrenoNelsonJosephTygar2010" class="citation journal cs1">Barreno, Marco; Nelson, Blaine; Joseph, Anthony D.; Tygar, J. D. (2010). <a rel="nofollow" class="external text" href="https://link.springer.com/content/pdf/10.1007/s10994-010-5188-5.pdf">"The security of machine learning"</a> <span class="cs1-format">(PDF)</span>. <i>Machine Learning</i>. <b>81</b> (2): <span class="nowrap">121–</span>148. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1007%2Fs10994-010-5188-5">10.1007/s10994-010-5188-5</a></span>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:2304759">2304759</a>.</cite></span>
</li>
<li id="cite_note-42"><span class="mw-cite-backlink"><b><a href="#cite_ref-42">^</a></b></span> <span class="reference-text"><cite id="CITEREFSikos2019" class="citation book cs1">Sikos, Leslie F. (2019). <i>AI in Cybersecurity</i>. Intelligent Systems Reference Library. Vol. 151. Cham: Springer. p. 50. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-319-98842-9">10.1007/978-3-319-98842-9</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-3-319-98841-2</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:259216663">259216663</a>.</cite></span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_4A2-43"><span class="mw-cite-backlink">^ <a href="#cite_ref-Adversarial_Machine_Learning_4A2_43-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Adversarial_Machine_Learning_4A2_43-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-Adversarial_Machine_Learning_4A2_43-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text">B. Biggio, G. Fumera, and F. Roli. "<a rel="nofollow" class="external text" href="http://pralab.diee.unica.it/en/node/657">Security evaluation of pattern classifiers under attack</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20180518055115/http://pralab.diee.unica.it/en/node/657">Archived</a> 2018-05-18 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a>". IEEE Transactions on Knowledge and Data Engineering, 26(4):984–996, 2014.</span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_5A2-44"><span class="mw-cite-backlink">^ <a href="#cite_ref-Adversarial_Machine_Learning_5A2_44-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Adversarial_Machine_Learning_5A2_44-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-Adversarial_Machine_Learning_5A2_44-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-Adversarial_Machine_Learning_5A2_44-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-Adversarial_Machine_Learning_5A2_44-4"><sup><i><b>e</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBiggioCoronaNelsonRubinstein2014" class="citation book cs1">Biggio, Battista; Corona, Igino; Nelson, Blaine; Rubinstein, Benjamin I. P.; Maiorca, Davide; Fumera, Giorgio; Giacinto, Giorgio; Roli, Fabio (2014). "Security Evaluation of Support Vector Machines in Adversarial Environments". <i>Support Vector Machines Applications</i>. Springer International Publishing. pp. <span class="nowrap">105–</span>153. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1401.7727">1401.7727</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-319-02300-7_4">10.1007/978-3-319-02300-7_4</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-3-319-02300-7</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:18666561">18666561</a>.</cite></span>
</li>
<li id="cite_note-45"><span class="mw-cite-backlink"><b><a href="#cite_ref-45">^</a></b></span> <span class="reference-text"><cite id="CITEREFHeinrichGrafChenLaurisch2020" class="citation journal cs1">Heinrich, Kai; Graf, Johannes; Chen, Ji; Laurisch, Jakob; Zschech, Patrick (2020-06-15). <a rel="nofollow" class="external text" href="https://aisel.aisnet.org/ecis2020_rp/166">"Fool Me Once, Shame On You, Fool Me Twice, Shame On Me: A Taxonomy of Attack and De-fense Patterns for AI Security"</a>. <i>ECIS 2020 Research Papers</i>.</cite></span>
</li>
<li id="cite_note-46"><span class="mw-cite-backlink"><b><a href="#cite_ref-46">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.techdigest.tv/2021/09/facebook-removes-15-billion-fake-accounts-in-two-years.html">"Facebook removes 15 Billion fake accounts in two years"</a>. <i>Tech Digest</i>. 2021-09-27<span class="reference-accessdate">. Retrieved <span class="nowrap">2022-06-08</span></span>.</cite></span>
</li>
<li id="cite_note-47"><span class="mw-cite-backlink"><b><a href="#cite_ref-47">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://nypost.com/2019/05/23/facebook-removed-3-billion-fake-accounts-in-just-6-months/">"Facebook removed 3 billion fake accounts in just 6 months"</a>. <i>New York Post</i>. Associated Press. 2019-05-23<span class="reference-accessdate">. Retrieved <span class="nowrap">2022-06-08</span></span>.</cite></span>
</li>
<li id="cite_note-48"><span class="mw-cite-backlink"><b><a href="#cite_ref-48">^</a></b></span> <span class="reference-text"><cite id="CITEREFSchwarzschildGoldblumGuptaDickerson2021" class="citation journal cs1">Schwarzschild, Avi; Goldblum, Micah; Gupta, Arjun; Dickerson, John P.; Goldstein, Tom (2021-07-01). <a rel="nofollow" class="external text" href="https://proceedings.mlr.press/v139/schwarzschild21a.html">"Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks"</a>. <i>International Conference on Machine Learning</i>. PMLR: <span class="nowrap">9389–</span>9398.</cite></span>
</li>
<li id="cite_note-49"><span class="mw-cite-backlink"><b><a href="#cite_ref-49">^</a></b></span> <span class="reference-text"><cite id="CITEREFShanDingPassanantiWu2023" class="citation arxiv cs1">Shan, Shawn; Ding, Wenxin; Passananti, Josephine; Wu, Stanley; Zheng, Haitao; Zhao, Ben Y. (2023). "Nightshade: Prompt-Specific Poisoning Attacks on Text-to-Image Generative Models". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2310.13828">2310.13828</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CR">cs.CR</a>].</cite></span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_15A2-50"><span class="mw-cite-backlink"><b><a href="#cite_ref-Adversarial_Machine_Learning_15A2_50-0">^</a></b></span> <span class="reference-text">B. Biggio, B. Nelson, and P. Laskov. "<a rel="nofollow" class="external text" href="http://pralab.diee.unica.it/en/node/751">Support vector machines under adversarial label noise</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200803190135/http://pralab.diee.unica.it/en/node/751">Archived</a> 2020-08-03 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a>". In Journal of Machine Learning Research – Proc. 3rd Asian Conf. Machine Learning, volume 20, pp. 97–112, 2011.</span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_29A2-51"><span class="mw-cite-backlink"><b><a href="#cite_ref-Adversarial_Machine_Learning_29A2_51-0">^</a></b></span> <span class="reference-text">M. Kloft and P. Laskov. "<a rel="nofollow" class="external text" href="http://www.jmlr.org/papers/volume13/kloft12b/kloft12b.pdf">Security analysis of online centroid anomaly detection</a>". Journal of Machine Learning Research, 13:3647–3690, 2012.</span>
</li>
<li id="cite_note-52"><span class="mw-cite-backlink"><b><a href="#cite_ref-52">^</a></b></span> <span class="reference-text"><cite id="CITEREFEdwards2023" class="citation web cs1">Edwards, Benj (2023-10-25). <a rel="nofollow" class="external text" href="https://arstechnica.com/information-technology/2023/10/university-of-chicago-researchers-seek-to-poison-ai-art-generators-with-nightshade/">"University of Chicago researchers seek to "poison" AI art generators with Nightshade"</a>. <i>Ars Technica</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-10-27</span></span>.</cite></span>
</li>
<li id="cite_note-53"><span class="mw-cite-backlink"><b><a href="#cite_ref-53">^</a></b></span> <span class="reference-text"><cite id="CITEREFRao" class="citation web cs1">Rao, Rahul. <a rel="nofollow" class="external text" href="https://www.scientificamerican.com/article/ai-generated-data-can-poison-future-ai-models/">"AI-Generated Data Can Poison Future AI Models"</a>. <i>Scientific American</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2024-06-22</span></span>.</cite></span>
</li>
<li id="cite_note-Baruch_2019-54"><span class="mw-cite-backlink"><b><a href="#cite_ref-Baruch_2019_54-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFBaruchBaruchGoldberg2019" class="citation journal cs1">Baruch, Gilad; Baruch, Moran; Goldberg, Yoav (2019). <a rel="nofollow" class="external text" href="https://proceedings.neurips.cc/paper/2019/hash/ec1c59141046cd1866bbbcdfb6ae31d4-Abstract.html">"A Little Is Enough: Circumventing Defenses For Distributed Learning"</a>. <i>Advances in Neural Information Processing Systems</i>. <b>32</b>. Curran Associates, Inc. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1902.06156">1902.06156</a></span>.</cite></span>
</li>
<li id="cite_note-55"><span class="mw-cite-backlink"><b><a href="#cite_ref-55">^</a></b></span> <span class="reference-text"><cite id="CITEREFEl-MhamdiGuerraouiGuirguisHoang2022" class="citation journal cs1">El-Mhamdi, El-Mahdi; Guerraoui, Rachid; Guirguis, Arsany; Hoang, Lê-Nguyên; Rouault, Sébastien (2022-05-26). <a rel="nofollow" class="external text" href="https://doi.org/10.1007%2Fs00446-022-00427-9">"Genuinely distributed Byzantine machine learning"</a>. <i>Distributed Computing</i>. <b>35</b> (4): <span class="nowrap">305–</span>331. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1905.03853">1905.03853</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1007%2Fs00446-022-00427-9">10.1007/s00446-022-00427-9</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1432-0452">1432-0452</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:249111966">249111966</a>.</cite></span>
</li>
<li id="cite_note-56"><span class="mw-cite-backlink"><b><a href="#cite_ref-56">^</a></b></span> <span class="reference-text"><cite id="CITEREFGoldwasserKimVaikuntanathanZamir2022" class="citation arxiv cs1">Goldwasser, S.; Kim, Michael P.; Vaikuntanathan, V.; Zamir, Or (2022). "Planting Undetectable Backdoors in Machine Learning Models". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2204.06974">2204.06974</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.LG">cs.LG</a>].</cite></span>
</li>
<li id="cite_note-:14-57"><span class="mw-cite-backlink">^ <a href="#cite_ref-:14_57-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:14_57-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBlanchardEl_MhamdiGuerraouiStainer2017" class="citation journal cs1">Blanchard, Peva; El Mhamdi, El Mahdi; Guerraoui, Rachid; Stainer, Julien (2017). <a rel="nofollow" class="external text" href="https://proceedings.neurips.cc/paper/2017/hash/f4b9ec30ad9f68f89b29639786cb62ef-Abstract.html">"Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent"</a>. <i>Advances in Neural Information Processing Systems</i>. <b>30</b>. Curran Associates, Inc.</cite></span>
</li>
<li id="cite_note-58"><span class="mw-cite-backlink"><b><a href="#cite_ref-58">^</a></b></span> <span class="reference-text"><cite id="CITEREFChenWangCharlesPapailiopoulos2018" class="citation journal cs1">Chen, Lingjiao; Wang, Hongyi; Charles, Zachary; Papailiopoulos, Dimitris (2018-07-03). <a rel="nofollow" class="external text" href="https://proceedings.mlr.press/v80/chen18l.html">"DRACO: Byzantine-resilient Distributed Training via Redundant Gradients"</a>. <i>International Conference on Machine Learning</i>. PMLR: <span class="nowrap">903–</span>912. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1803.09877">1803.09877</a></span>.</cite></span>
</li>
<li id="cite_note-59"><span class="mw-cite-backlink"><b><a href="#cite_ref-59">^</a></b></span> <span class="reference-text"><cite id="CITEREFMhamdiGuerraouiRouault2018" class="citation journal cs1">Mhamdi, El Mahdi El; Guerraoui, Rachid; Rouault, Sébastien (2018-07-03). <a rel="nofollow" class="external text" href="https://proceedings.mlr.press/v80/mhamdi18a.html">"The Hidden Vulnerability of Distributed Learning in Byzantium"</a>. <i>International Conference on Machine Learning</i>. PMLR: <span class="nowrap">3521–</span>3530. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1802.07927">1802.07927</a></span>.</cite></span>
</li>
<li id="cite_note-60"><span class="mw-cite-backlink"><b><a href="#cite_ref-60">^</a></b></span> <span class="reference-text"><cite id="CITEREFAllen-ZhuEbrahimianghazaniLiAlistarh2020" class="citation arxiv cs1">Allen-Zhu, Zeyuan; Ebrahimianghazani, Faeze; Li, Jerry; Alistarh, Dan (2020-09-28). "Byzantine-Resilient Non-Convex Stochastic Gradient Descent". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2012.14368">2012.14368</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.LG">cs.LG</a>].</cite> <a rel="nofollow" class="external text" href="https://openreview.net/forum?id=PbEHqvFtcS">Review</a></span>
</li>
<li id="cite_note-61"><span class="mw-cite-backlink"><b><a href="#cite_ref-61">^</a></b></span> <span class="reference-text"><cite id="CITEREFMhamdiGuerraouiRouault2020" class="citation conference cs1">Mhamdi, El Mahdi El; Guerraoui, Rachid; Rouault, Sébastien (2020-09-28). <a rel="nofollow" class="external text" href="https://infoscience.epfl.ch/record/287261"><i>Distributed Momentum for Byzantine-resilient Stochastic Gradient Descent</i></a>. 9th International Conference on Learning Representations (ICLR), May 4–8, 2021 (virtual conference)<span class="reference-accessdate">. Retrieved <span class="nowrap">2022-10-20</span></span>.</cite> <a rel="nofollow" class="external text" href="https://openreview.net/forum?id=H8UHdhWG6A3">Review</a></span>
</li>
<li id="cite_note-62"><span class="mw-cite-backlink"><b><a href="#cite_ref-62">^</a></b></span> <span class="reference-text"><cite id="CITEREFDataDiggavi2021" class="citation journal cs1">Data, Deepesh; Diggavi, Suhas (2021-07-01). <a rel="nofollow" class="external text" href="https://proceedings.mlr.press/v139/data21a.html">"Byzantine-Resilient High-Dimensional SGD with Local Iterations on Heterogeneous Data"</a>. <i>International Conference on Machine Learning</i>. PMLR: <span class="nowrap">2478–</span>2488.</cite></span>
</li>
<li id="cite_note-63"><span class="mw-cite-backlink"><b><a href="#cite_ref-63">^</a></b></span> <span class="reference-text"><cite id="CITEREFKarimireddyHeJaggi2021" class="citation arxiv cs1">Karimireddy, Sai Praneeth; He, Lie; Jaggi, Martin (2021-09-29). "Byzantine-Robust Learning on Heterogeneous Datasets via Bucketing". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2006.09365">2006.09365</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.LG">cs.LG</a>].</cite> <a rel="nofollow" class="external text" href="https://openreview.net/forum?id=jXKKDEi5vJt">Review</a></span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_36A2-64"><span class="mw-cite-backlink"><b><a href="#cite_ref-Adversarial_Machine_Learning_36A2_64-0">^</a></b></span> <span class="reference-text">B. Nelson, B. I. Rubinstein, L. Huang, A. D. Joseph, S. J. Lee, S. Rao, and J. D. Tygar. "<a rel="nofollow" class="external text" href="http://www.jmlr.org/papers/volume13/nelson12a/nelson12a.pdf">Query strategies for evading convex-inducing classifiers</a>". J. Mach. Learn. Res., 13:1293–1332, 2012</span>
</li>
<li id="cite_note-65"><span class="mw-cite-backlink"><b><a href="#cite_ref-65">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://cleverhans.io/2020/04/06/stealing-bert.html">"How to steal modern NLP systems with gibberish?"</a>. <i>cleverhans-blog</i>. 2020-04-06<span class="reference-accessdate">. Retrieved <span class="nowrap">2020-10-15</span></span>.</cite></span>
</li>
<li id="cite_note-:12-66"><span class="mw-cite-backlink">^ <a href="#cite_ref-:12_66-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:12_66-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:12_66-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-:12_66-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-:12_66-4"><sup><i><b>e</b></i></sup></a> <a href="#cite_ref-:12_66-5"><sup><i><b>f</b></i></sup></a> <a href="#cite_ref-:12_66-6"><sup><i><b>g</b></i></sup></a> <a href="#cite_ref-:12_66-7"><sup><i><b>h</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFWangXiangGaoDing2020" class="citation arxiv cs1">Wang, Xinran; Xiang, Yu; Gao, Jun; Ding, Jie (2020-09-13). "Information Laundering for Model Privacy". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2009.06112">2009.06112</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CR">cs.CR</a>].</cite></span>
</li>
<li id="cite_note-:6-67"><span class="mw-cite-backlink">^ <a href="#cite_ref-:6_67-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:6_67-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFDickson2021" class="citation web cs1">Dickson, Ben (2021-04-23). <a rel="nofollow" class="external text" href="https://bdtechtalks.com/2021/04/23/machine-learning-membership-inference-attacks/">"Machine learning: What are membership inference attacks?"</a>. <i>TechTalks</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-11-07</span></span>.</cite></span>
</li>
<li id="cite_note-68"><span class="mw-cite-backlink"><b><a href="#cite_ref-68">^</a></b></span> <span class="reference-text"><cite id="CITEREFGoodfellowShlensSzegedy2015" class="citation conference cs1">Goodfellow, Ian J.; Shlens, Jonathon; Szegedy, Christian (2015). <i>Explaining and Harnessing Adversarial Examples</i>. International Conference on Learning Representations (ICLR).</cite></span>
</li>
<li id="cite_note-69"><span class="mw-cite-backlink"><b><a href="#cite_ref-69">^</a></b></span> <span class="reference-text"><cite id="CITEREFRibeiroZachariahBachSchön2023" class="citation conference cs1">Ribeiro, Antonio H.; Zachariah, Dave; Bach, Francis; Schön, Thomas B. (2023). <a rel="nofollow" class="external text" href="https://openreview.net/forum?id=K8gLHZIgVW"><i>Regularization properties of adversarially-trained linear regression</i></a>. Thirty-seventh Conference on Neural Information Processing Systems.</cite></span>
</li>
<li id="cite_note-70"><span class="mw-cite-backlink"><b><a href="#cite_ref-70">^</a></b></span> <span class="reference-text"><cite id="CITEREFTsiprasSanturkarEngstromTurner2019" class="citation conference cs1">Tsipras, Dimitris; Santurkar, Shibani; Engstrom, Logan; Turner, Alexander; Ma, Aleksander (2019). <i>Robustness May Be At Odds with Accuracy</i>. International Conference for Learning Representations.</cite></span>
</li>
<li id="cite_note-71"><span class="mw-cite-backlink"><b><a href="#cite_ref-71">^</a></b></span> <span class="reference-text"><cite id="CITEREFDanWeiRavikumar2020" class="citation conference cs1">Dan, C.; Wei, Y.; Ravikumar, P. (2020). <a rel="nofollow" class="external text" href="https://proceedings.mlr.press/v119/dan20b.html"><i>Sharp statistical guarantees for adversarially robust Gaussian classification</i></a>. International Conference on Machine Learning.</cite></span>
</li>
<li id="cite_note-72"><span class="mw-cite-backlink"><b><a href="#cite_ref-72">^</a></b></span> <span class="reference-text"><cite id="CITEREFJavanmardSoltanolkotabiHassani2020" class="citation conference cs1">Javanmard, A.; Soltanolkotabi, M.; Hassani, H. (2020). <a rel="nofollow" class="external text" href="http://proceedings.mlr.press/v125/javanmard20a.html"><i>Precise tradeoffs in adversarial training for linear regression</i></a>. Conference on Learning Theory.</cite></span>
</li>
<li id="cite_note-73"><span class="mw-cite-backlink"><b><a href="#cite_ref-73">^</a></b></span> <span class="reference-text"><cite id="CITEREFRibeiroSchön2023" class="citation journal cs1">Ribeiro, A. H.; Schön, T. B. (2023). "Overparameterized Linear Regression under Adversarial Attacks". <i>IEEE Transactions on Signal Processing</i>. <b>71</b>: <span class="nowrap">601–</span>614. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2204.06274">2204.06274</a></span>. <a href="Bibcode_(identifier)" class="mw-redirect" title="Bibcode (identifier)">Bibcode</a>:<a rel="nofollow" class="external text" href="https://ui.adsabs.harvard.edu/abs/2023ITSP...71..601R">2023ITSP...71..601R</a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FTSP.2023.3246228">10.1109/TSP.2023.3246228</a>.</cite></span>
</li>
<li id="cite_note-74"><span class="mw-cite-backlink"><b><a href="#cite_ref-74">^</a></b></span> <span class="reference-text"><cite id="CITEREFYinKannanBartlett2019" class="citation conference cs1">Yin, D.; Kannan, R.; Bartlett, P. (2019). <a rel="nofollow" class="external text" href="https://proceedings.mlr.press/v97/yin19b.html"><i>Rademacher Complexity for Adversarially Robust Generalization</i></a>. International Conference on Machine Learning.</cite></span>
</li>
<li id="cite_note-75"><span class="mw-cite-backlink"><b><a href="#cite_ref-75">^</a></b></span> <span class="reference-text"><cite id="CITEREFRibeiroZachariahBachSchön2023" class="citation cs2">Ribeiro, Antônio H.; Zachariah, Dave; Bach, Francis; Schön, Thomas B. (2023-10-16), <i>Regularization properties of adversarially-trained linear regression</i>, <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2310.10807">2310.10807</a></span></cite></span>
</li>
<li id="cite_note-76"><span class="mw-cite-backlink"><b><a href="#cite_ref-76">^</a></b></span> <span class="reference-text"><cite id="CITEREFGoodfellowShlensSzegedy2015" class="citation journal cs1">Goodfellow, Ian; Shlens, Jonathan; Szegedy, Christian (2015). "Explaining and Harnessing Adversarial Examples". <i>International Conference on Learning Representations</i>. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1412.6572">1412.6572</a></span>.</cite></span>
</li>
<li id="cite_note-77"><span class="mw-cite-backlink"><b><a href="#cite_ref-77">^</a></b></span> <span class="reference-text"><cite id="CITEREFPieterPapernotGoodfellowDuan2017" class="citation book cs1">Pieter, Huang; Papernot, Sandy; Goodfellow, Nicolas; Duan, Ian; Abbeel, Yan (2017-02-07). <i>Adversarial Attacks on Neural Network Policies</i>. <a href="OCLC_(identifier)" class="mw-redirect" title="OCLC (identifier)">OCLC</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/oclc/1106256905">1106256905</a>.</cite></span>
</li>
<li id="cite_note-78"><span class="mw-cite-backlink"><b><a href="#cite_ref-78">^</a></b></span> <span class="reference-text"><cite id="CITEREFKorkmaz2022" class="citation journal cs1">Korkmaz, Ezgi (2022). "Deep Reinforcement Learning Policies Learn Shared Adversarial Features Across MDPs". <i>Thirty-Sixth AAAI Conference on Artificial Intelligence (AAAI-22)</i>. <b>36</b> (7): <span class="nowrap">7229–</span>7238. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2112.09025">2112.09025</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1609%2Faaai.v36i7.20684">10.1609/aaai.v36i7.20684</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:245219157">245219157</a>.</cite></span>
</li>
<li id="cite_note-79"><span class="mw-cite-backlink"><b><a href="#cite_ref-79">^</a></b></span> <span class="reference-text"><cite id="CITEREFCarliniWagner2018" class="citation book cs1">Carlini, Nicholas; Wagner, David (2018). "Audio Adversarial Examples: Targeted Attacks on Speech-to-Text". <i>2018 IEEE Security and Privacy Workshops (SPW)</i>. pp. <span class="nowrap">1–</span>7. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1801.01944">1801.01944</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSPW.2018.00009">10.1109/SPW.2018.00009</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-5386-8276-0</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:4475201">4475201</a>.</cite></span>
</li>
<li id="cite_note-80"><span class="mw-cite-backlink"><b><a href="#cite_ref-80">^</a></b></span> <span class="reference-text"><cite id="CITEREFJagielskiOpreaBiggioLiu2018" class="citation book cs1">Jagielski, Matthew; Oprea, Alina; Biggio, Battista; Liu, Chang; Nita-Rotaru, Cristina; Li, Bo (May 2018). "Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression Learning". <i>2018 IEEE Symposium on Security and Privacy (SP)</i>. IEEE. pp. <span class="nowrap">19–</span>35. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1804.00308">1804.00308</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2Fsp.2018.00057">10.1109/sp.2018.00057</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-5386-4353-2</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:4551073">4551073</a>.</cite></span>
</li>
<li id="cite_note-81"><span class="mw-cite-backlink"><b><a href="#cite_ref-81">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://openai.com/blog/adversarial-example-research/">"Attacking Machine Learning with Adversarial Examples"</a>. <i>OpenAI</i>. 2017-02-24<span class="reference-accessdate">. Retrieved <span class="nowrap">2020-10-15</span></span>.</cite></span>
</li>
<li id="cite_note-82"><span class="mw-cite-backlink"><b><a href="#cite_ref-82">^</a></b></span> <span class="reference-text"><cite id="CITEREFGuDolan-GavittGarg2019" class="citation arxiv cs1">Gu, Tianyu; Dolan-Gavitt, Brendan; Garg, Siddharth (2019-03-11). "BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1708.06733">1708.06733</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CR">cs.CR</a>].</cite></span>
</li>
<li id="cite_note-83"><span class="mw-cite-backlink"><b><a href="#cite_ref-83">^</a></b></span> <span class="reference-text"><cite id="CITEREFVealeBinnsEdwards2018" class="citation journal cs1">Veale, Michael; Binns, Reuben; Edwards, Lilian (2018-11-28). <a rel="nofollow" class="external text" href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6191664">"Algorithms that remember: model inversion attacks and data protection law"</a>. <i>Philosophical Transactions. Series A, Mathematical, Physical, and Engineering Sciences</i>. <b>376</b> (2133). <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1807.04644">1807.04644</a></span>. <a href="Bibcode_(identifier)" class="mw-redirect" title="Bibcode (identifier)">Bibcode</a>:<a rel="nofollow" class="external text" href="https://ui.adsabs.harvard.edu/abs/2018RSPTA.37680083V">2018RSPTA.37680083V</a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1098%2Frsta.2018.0083">10.1098/rsta.2018.0083</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1364-503X">1364-503X</a>. <a href="PMC_(identifier)" class="mw-redirect" title="PMC (identifier)">PMC</a> <span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6191664">6191664</a></span>. <a href="PMID_(identifier)" class="mw-redirect" title="PMID (identifier)">PMID</a> <a rel="nofollow" class="external text" href="https://pubmed.ncbi.nlm.nih.gov/30322998">30322998</a>.</cite></span>
</li>
<li id="cite_note-84"><span class="mw-cite-backlink"><b><a href="#cite_ref-84">^</a></b></span> <span class="reference-text"><cite id="CITEREFShokriStronatiSongShmatikov2017" class="citation arxiv cs1">Shokri, Reza; Stronati, Marco; Song, Congzheng; Shmatikov, Vitaly (2017-03-31). "Membership Inference Attacks against Machine Learning Models". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1610.05820">1610.05820</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CR">cs.CR</a>].</cite></span>
</li>
<li id="cite_note-Explaining_and_Harnessing_Adversari2-85"><span class="mw-cite-backlink">^ <a href="#cite_ref-Explaining_and_Harnessing_Adversari2_85-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Explaining_and_Harnessing_Adversari2_85-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFGoodfellowShlensSzegedy2015" class="citation arxiv cs1">Goodfellow, Ian J.; Shlens, Jonathon; Szegedy, Christian (2015-03-20). "Explaining and Harnessing Adversarial Examples". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1412.6572">1412.6572</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/stat.ML">stat.ML</a>].</cite></span>
</li>
<li id="cite_note-86"><span class="mw-cite-backlink"><b><a href="#cite_ref-86">^</a></b></span> <span class="reference-text"><cite id="CITEREFMadryMakelovSchmidtTsipras2019" class="citation arxiv cs1">Madry, Aleksander; Makelov, Aleksandar; Schmidt, Ludwig; Tsipras, Dimitris; Vladu, Adrian (2019-09-04). "Towards Deep Learning Models Resistant to Adversarial Attacks". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1706.06083">1706.06083</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/stat.ML">stat.ML</a>].</cite></span>
</li>
<li id="cite_note-87"><span class="mw-cite-backlink"><b><a href="#cite_ref-87">^</a></b></span> <span class="reference-text"><cite id="CITEREFCarliniWagner2017" class="citation arxiv cs1">Carlini, Nicholas; Wagner, David (2017-03-22). "Towards Evaluating the Robustness of Neural Networks". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1608.04644">1608.04644</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CR">cs.CR</a>].</cite></span>
</li>
<li id="cite_note-88"><span class="mw-cite-backlink"><b><a href="#cite_ref-88">^</a></b></span> <span class="reference-text"><cite id="CITEREFBrownManéRoyAbadi2018" class="citation arxiv cs1">Brown, Tom B.; Mané, Dandelion; Roy, Aurko; Abadi, Martín; Gilmer, Justin (2018-05-16). "Adversarial Patch". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1712.09665">1712.09665</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CV">cs.CV</a>].</cite></span>
</li>
<li id="cite_note-89"><span class="mw-cite-backlink"><b><a href="#cite_ref-89">^</a></b></span> <span class="reference-text"><cite id="CITEREFGuoZhaoLiDuan2021" class="citation journal cs1">Guo, Sensen; Zhao, Jinxiong; Li, Xiaoyu; Duan, Junhong; Mu, Dejun; Jing, Xiao (2021-04-24). <a rel="nofollow" class="external text" href="https://doi.org/10.1155%2F2021%2F5578335">"A Black-Box Attack Method against Machine-Learning-Based Anomaly Network Flow Detection Models"</a>. <i>Security and Communication Networks</i>. <b>2021</b>. e5578335. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1155%2F2021%2F5578335">10.1155/2021/5578335</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1939-0114">1939-0114</a>.</cite></span>
</li>
<li id="cite_note-:4-90"><span class="mw-cite-backlink">^ <a href="#cite_ref-:4_90-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:4_90-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFGomes2018" class="citation web cs1">Gomes, Joao (2018-01-17). <a rel="nofollow" class="external text" href="https://medium.com/onfido-tech/adversarial-attacks-and-defences-for-convolutional-neural-networks-66915ece52e7">"Adversarial Attacks and Defences for Convolutional Neural Networks"</a>. <i>Onfido Tech</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-10-23</span></span>.</cite></span>
</li>
<li id="cite_note-91"><span class="mw-cite-backlink"><b><a href="#cite_ref-91">^</a></b></span> <span class="reference-text"><cite id="CITEREFGuoGardnerYouWilson2019" class="citation journal cs1">Guo, Chuan; Gardner, Jacob; You, Yurong; Wilson, Andrew Gordon; Weinberger, Kilian (2019-05-24). <a rel="nofollow" class="external text" href="https://proceedings.mlr.press/v97/guo19a.html">"Simple Black-box Adversarial Attacks"</a>. <i>Proceedings of the 36th International Conference on Machine Learning</i>. PMLR: <span class="nowrap">2484–</span>2493. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1905.07121">1905.07121</a></span>.</cite></span>
</li>
<li id="cite_note-92"><span class="mw-cite-backlink"><b><a href="#cite_ref-92">^</a></b></span> <span class="reference-text">Kilian Weinberger. On the importance of deconstruction in machine learning research.ML-Retrospectives @ NeurIPS 2020, 2020.<a rel="nofollow" class="external free" href="https://slideslive.com/38938218/the-importance-of-deconstruction">https://slideslive.com/38938218/the-importance-of-deconstruction</a></span>
</li>
<li id="cite_note-:7-93"><span class="mw-cite-backlink">^ <a href="#cite_ref-:7_93-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:7_93-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:7_93-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-:7_93-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-:7_93-4"><sup><i><b>e</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFAndriushchenkoCroceFlammarionHein2020" class="citation book cs1">Andriushchenko, Maksym; Croce, Francesco; Flammarion, Nicolas; Hein, Matthias (2020). <a rel="nofollow" class="external text" href="https://link.springer.com/chapter/10.1007/978-3-030-58592-1_29">"Square Attack: A Query-Efficient Black-Box Adversarial Attack via Random Search"</a>. In Vedaldi, Andrea; Bischof, Horst; Brox, Thomas; Frahm, Jan-Michael (eds.). <i>Computer Vision – ECCV 2020</i>. Lecture Notes in Computer Science. Vol. 12368. Cham: Springer International Publishing. pp. <span class="nowrap">484–</span>501. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1912.00049">1912.00049</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-030-58592-1_29">10.1007/978-3-030-58592-1_29</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-3-030-58592-1</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:208527215">208527215</a>.</cite></span>
</li>
<li id="cite_note-:8-94"><span class="mw-cite-backlink">^ <a href="#cite_ref-:8_94-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:8_94-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:8_94-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-:8_94-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-:8_94-4"><sup><i><b>e</b></i></sup></a> <a href="#cite_ref-:8_94-5"><sup><i><b>f</b></i></sup></a> <a href="#cite_ref-:8_94-6"><sup><i><b>g</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFChenJordanWainwright2019" class="citation arxiv cs1">Chen, Jianbo; Jordan, Michael I.; Wainwright, Martin J. (2019). "HopSkipJumpAttack: A Query-Efficient Decision-Based Attack". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1904.02144">1904.02144</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.LG">cs.LG</a>].</cite> <a rel="nofollow" class="external text" href="https://www.youtube.com/watch?v=vkCifg2rp34">YouTube presentation</a></span>
</li>
<li id="cite_note-95"><span class="mw-cite-backlink"><b><a href="#cite_ref-95">^</a></b></span> <span class="reference-text"><cite id="CITEREFAndriushchenkoCroceFlammarionHein2020" class="citation arxiv cs1">Andriushchenko, Maksym; Croce, Francesco; Flammarion, Nicolas; Hein, Matthias (2020-07-29). "Square Attack: a query-efficient black-box adversarial attack via random search". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1912.00049">1912.00049</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.LG">cs.LG</a>].</cite></span>
</li>
<li id="cite_note-96"><span class="mw-cite-backlink"><b><a href="#cite_ref-96">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://davideliu.com/2020/06/21/black-box-decision-based-attacks-on-images/">"Black-box decision-based attacks on images"</a>. <i>KejiTech</i>. 2020-06-21<span class="reference-accessdate">. Retrieved <span class="nowrap">2021-10-25</span></span>.</cite></span>
</li>
<li id="cite_note-:9-97"><span class="mw-cite-backlink">^ <a href="#cite_ref-:9_97-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:9_97-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFGoodfellowShlensSzegedy2015" class="citation arxiv cs1">Goodfellow, Ian J.; Shlens, Jonathon; Szegedy, Christian (2015-03-20). "Explaining and Harnessing Adversarial Examples". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1412.6572">1412.6572</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/stat.ML">stat.ML</a>].</cite></span>
</li>
<li id="cite_note-:11-98"><span class="mw-cite-backlink">^ <a href="#cite_ref-:11_98-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:11_98-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.tensorflow.org/tutorials/generative/adversarial_fgsm">"Adversarial example using FGSM | TensorFlow Core"</a>. <i>TensorFlow</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-10-24</span></span>.</cite></span>
</li>
<li id="cite_note-:10-99"><span class="mw-cite-backlink"><b><a href="#cite_ref-:10_99-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFTsui2018" class="citation web cs1">Tsui, Ken (2018-08-22). <a rel="nofollow" class="external text" href="https://towardsdatascience.com/perhaps-the-simplest-introduction-of-adversarial-examples-ever-c0839a759b8d">"Perhaps the Simplest Introduction of Adversarial Examples Ever"</a>. <i>Medium</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-10-24</span></span>.</cite></span>
</li>
<li id="cite_note-coronafigueroaa23unaligned-100"><span class="mw-cite-backlink"><b><a href="#cite_ref-coronafigueroaa23unaligned_100-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFCorona-FigueroaBond-TaylorBhowmikGaus2023" class="citation conference cs1">Corona-Figueroa, Abril; Bond-Taylor, Sam; Bhowmik, Neelanjan; Gaus, Yona Falinie A.; Breckon, Toby P.; Shum, Hubert P. H.; Willcocks, Chris G. (2023). <i>Unaligned 2D to 3D Translation with Conditional Vector-Quantized Code Diffusion using Transformers</i>. IEEE/CVF. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2308.14152">2308.14152</a></span>.</cite></span>
</li>
<li id="cite_note-:5-101"><span class="mw-cite-backlink">^ <a href="#cite_ref-:5_101-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:5_101-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFCarliniWagner2017" class="citation arxiv cs1">Carlini, Nicholas; Wagner, David (2017-03-22). "Towards Evaluating the Robustness of Neural Networks". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1608.04644">1608.04644</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.CR">cs.CR</a>].</cite></span>
</li>
<li id="cite_note-102"><span class="mw-cite-backlink"><b><a href="#cite_ref-102">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://richardjordan.com/ucdfk/carlini-wagner-attack">"carlini wagner attack"</a>. <i>richardjordan.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-10-23</span></span>.</cite></span>
</li>
<li id="cite_note-103"><span class="mw-cite-backlink"><b><a href="#cite_ref-103">^</a></b></span> <span class="reference-text"><cite id="CITEREFPlotz2018" class="citation web cs1">Plotz, Mike (2018-11-26). <a rel="nofollow" class="external text" href="https://medium.com/@hyponymous/paper-summary-adversarial-examples-are-not-easily-detected-bypassing-ten-detection-methods-faf040e54e93">"Paper Summary: Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods"</a>. <i>Medium</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-10-23</span></span>.</cite></span>
</li>
<li id="cite_note-104"><span class="mw-cite-backlink"><b><a href="#cite_ref-104">^</a></b></span> <span class="reference-text"><cite id="CITEREFKishor_Datta_GuptaAkhtarDasgupta2021" class="citation journal cs1">Kishor Datta Gupta; Akhtar, Zahid; Dasgupta, Dipankar (2021). "Determining Sequence of Image Processing Technique (IPT) to Detect Adversarial Attacks". <i>SN Computer Science</i>. <b>2</b> (5): 383. <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2007.00337">2007.00337</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2Fs42979-021-00773-8">10.1007/s42979-021-00773-8</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/2662-995X">2662-995X</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:220281087">220281087</a>.</cite></span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_22A2-105"><span class="mw-cite-backlink"><b><a href="#cite_ref-Adversarial_Machine_Learning_22A2_105-0">^</a></b></span> <span class="reference-text">O. Dekel, O. Shamir, and L. Xiao. "<a rel="nofollow" class="external text" href="https://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/DekelShXi09.pdf">Learning to classify with missing and corrupted features</a>". Machine Learning, 81:149–178, 2010.</span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_45A2-106"><span class="mw-cite-backlink"><b><a href="#cite_ref-Adversarial_Machine_Learning_45A2_106-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFLiuChawla2010" class="citation journal cs1">Liu, Wei; Chawla, Sanjay (2010). <a rel="nofollow" class="external text" href="https://link.springer.com/content/pdf/10.1007/s10994-010-5199-2.pdf">"Mining adversarial patterns via regularized loss minimization"</a> <span class="cs1-format">(PDF)</span>. <i>Machine Learning</i>. <b>81</b>: <span class="nowrap">69–</span>83. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1007%2Fs10994-010-5199-2">10.1007/s10994-010-5199-2</a></span>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:17497168">17497168</a>.</cite></span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_10A2-107"><span class="mw-cite-backlink"><b><a href="#cite_ref-Adversarial_Machine_Learning_10A2_107-0">^</a></b></span> <span class="reference-text">B. Biggio, G. Fumera, and F. Roli. "<a rel="nofollow" class="external text" href="http://pralab.diee.unica.it/en/node/642">Evade hard multiple classifier systems</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20150115114531/http://pralab.diee.unica.it/en/node/642">Archived</a> 2015-01-15 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a>". In O. Okun and G. Valentini, editors, Supervised and Unsupervised Ensemble Methods and Their Applications, volume 245 of Studies in Computational Intelligence, pages 15–38. Springer Berlin / Heidelberg, 2009.</span>
</li>
<li id="cite_note-Adversarial_Machine_Learning_41A2-108"><span class="mw-cite-backlink"><b><a href="#cite_ref-Adversarial_Machine_Learning_41A2_108-0">^</a></b></span> <span class="reference-text">B. I. P. Rubinstein, P. L. Bartlett, L. Huang, and N. Taft. "<a href="https://arxiv.org/abs/0911.5708" class="extiw external" title="arxiv:0911.5708">Learning in a large function space: Privacy- preserving mechanisms for svm learning</a>". Journal of Privacy and Confidentiality, 4(1):65–100, 2012.</span>
</li>
<li id="cite_note-feature_select2-109"><span class="mw-cite-backlink"><b><a href="#cite_ref-feature_select2_109-0">^</a></b></span> <span class="reference-text">M. Kantarcioglu, B. Xi, C. Clifton. <a rel="nofollow" class="external text" href="http://www.stat.purdue.edu/~xbw/research/BoweiXi.AdversarialClassification2010.pdf">"Classifier Evaluation and Attribute Selection against Active Adversaries"</a>. Data Min. Knowl. Discov., 22:291–335, January 2011.</span>
</li>
<li id="cite_note-110"><span class="mw-cite-backlink"><b><a href="#cite_ref-110">^</a></b></span> <span class="reference-text"><cite id="CITEREFChivukulaYangLiuZhu2020" class="citation journal cs1">Chivukula, Aneesh; Yang, Xinghao; Liu, Wei; Zhu, Tianqing; Zhou, Wanlei (2020). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/8986751">"Game Theoretical Adversarial Deep Learning with Variational Adversaries"</a>. <i>IEEE Transactions on Knowledge and Data Engineering</i>. <b>33</b> (11): <span class="nowrap">3568–</span>3581. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FTKDE.2020.2972320">10.1109/TKDE.2020.2972320</a>. <a href="Hdl_(identifier)" class="mw-redirect" title="Hdl (identifier)">hdl</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://hdl.handle.net/10453%2F145751">10453/145751</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1558-2191">1558-2191</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:213845560">213845560</a>.</cite></span>
</li>
<li id="cite_note-111"><span class="mw-cite-backlink"><b><a href="#cite_ref-111">^</a></b></span> <span class="reference-text"><cite id="CITEREFChivukulaLiu2019" class="citation journal cs1">Chivukula, Aneesh Sreevallabh; Liu, Wei (2019). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/8399545">"Adversarial Deep Learning Models with Multiple Adversaries"</a>. <i>IEEE Transactions on Knowledge and Data Engineering</i>. <b>31</b> (6): <span class="nowrap">1066–</span>1079. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FTKDE.2018.2851247">10.1109/TKDE.2018.2851247</a>. <a href="Hdl_(identifier)" class="mw-redirect" title="Hdl (identifier)">hdl</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://hdl.handle.net/10453%2F136227">10453/136227</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1558-2191">1558-2191</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:67024195">67024195</a>.</cite></span>
</li>
<li id="cite_note-112"><span class="mw-cite-backlink"><b><a href="#cite_ref-112">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.iarpa.gov/index.php/research-programs/trojai">"TrojAI"</a>. <i>www.iarpa.gov</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2020-10-14</span></span>.</cite></span>
</li>
<li id="cite_note-113"><span class="mw-cite-backlink"><b><a href="#cite_ref-113">^</a></b></span> <span class="reference-text"><cite id="CITEREFAthalyeCarliniWagner2018" class="citation arxiv cs1">Athalye, Anish; Carlini, Nicholas; Wagner, David (2018-02-01). "Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Example". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1802.00420v1">1802.00420v1</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.LG">cs.LG</a>].</cite></span>
</li>
<li id="cite_note-114"><span class="mw-cite-backlink"><b><a href="#cite_ref-114">^</a></b></span> <span class="reference-text"><cite id="CITEREFHeWeiChenCarlini2017" class="citation arxiv cs1">He, Warren; Wei, James; Chen, Xinyun; Carlini, Nicholas; Song, Dawn (2017-06-15). "Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong". <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/1706.04701">1706.04701</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs.LG">cs.LG</a>].</cite></span>
</li>
<li id="cite_note-115"><span class="mw-cite-backlink"><b><a href="#cite_ref-115">^</a></b></span> <span class="reference-text"><cite id="CITEREFYerlikayaBahtiyar2022" class="citation journal cs1">Yerlikaya, Fahri Anıl; Bahtiyar, Şerif (2022-07-14). <a rel="nofollow" class="external text" href="https://doi.org/10.1016/j.eswa.2022.118101">"Data poisoning attacks against machine learning algorithms"</a>. <i>Expert Systems with Applications</i>. <b>208</b>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1016%2Fj.eswa.2022.118101">10.1016/j.eswa.2022.118101</a> – via Elsevier Science Direct.</cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://atlas.mitre.org/">MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems</a></li>
<li><a rel="nofollow" class="external text" href="https://csrc.nist.gov/publications/detail/nistir/8269/draft">NIST 8269 Draft: A Taxonomy and Terminology of Adversarial Machine Learning</a></li>
<li>NIPS 2007 Workshop on <a rel="nofollow" class="external text" href="https://web.archive.org/web/20120108072159/http://nips.cc/Conferences/2007/Program/event.php?ID=615">Machine Learning in Adversarial Environments for Computer Security</a></li>
<li><a rel="nofollow" class="external text" href="http://pralab.diee.unica.it/en/ALFASVMLib">AlfaSVMLib</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200924221614/http://pralab.diee.unica.it/en/ALFASVMLib">Archived</a> 2020-09-24 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a> – Adversarial Label Flip Attacks against Support Vector Machines</li>
<li><cite id="CITEREFLaskovLippmann2010" class="citation journal cs1">Laskov, Pavel; Lippmann, Richard (2010). "Machine learning in adversarial environments". <i>Machine Learning</i>. <b>81</b> (2): <span class="nowrap">115–</span>119. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2Fs10994-010-5207-6">10.1007/s10994-010-5207-6</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:12567278">12567278</a>.</cite></li>
<li>Dagstuhl Perspectives Workshop on "<a rel="nofollow" class="external text" href="https://www.dagstuhl.de/en/seminars/seminar-calendar/seminar-details/12371">Machine Learning Methods for Computer Security</a>"</li>
<li>Workshop on <a rel="nofollow" class="external text" href="http://aisec.cc/">Artificial Intelligence and Security</a>, (AISec) Series</li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Artificial_intelligence_(AI)426" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><div id="Artificial_intelligence_(AI)426" style="font-size:114%;margin:0 4em"><a href="Artificial_intelligence" title="Artificial intelligence">Artificial intelligence</a> (AI)</div></th></tr><tr><td class="navbox-abovebelow" colspan="2"><div>
<ul><li><a href="History_of_artificial_intelligence" title="History of artificial intelligence">History</a>
<ul><li><a href="Timeline_of_artificial_intelligence" title="Timeline of artificial intelligence">timeline</a></li></ul></li>
<li><a href="List_of_artificial_intelligence_companies" title="List of artificial intelligence companies">Companies</a></li>
<li><a href="List_of_artificial_intelligence_projects" title="List of artificial intelligence projects">Projects</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Concepts</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Parameter" title="Parameter">Parameter</a>
<ul><li><a href="Hyperparameter_(machine_learning)" title="Hyperparameter (machine learning)">Hyperparameter</a></li></ul></li>
<li><a href="Loss_functions_for_classification" title="Loss functions for classification">Loss functions</a></li>
<li><a href="Regression_analysis" title="Regression analysis">Regression</a>
<ul><li><a href="Bias%E2%80%93variance_tradeoff" title="Bias–variance tradeoff">Bias–variance tradeoff</a></li>
<li><a href="Double_descent" title="Double descent">Double descent</a></li>
<li><a href="Overfitting" title="Overfitting">Overfitting</a></li></ul></li>
<li><a href="Cluster_analysis" title="Cluster analysis">Clustering</a></li>
<li><a href="Gradient_descent" title="Gradient descent">Gradient descent</a>
<ul><li><a href="Stochastic_gradient_descent" title="Stochastic gradient descent">SGD</a></li>
<li><a href="Quasi-Newton_method" title="Quasi-Newton method">Quasi-Newton method</a></li>
<li><a href="Conjugate_gradient_method" title="Conjugate gradient method">Conjugate gradient method</a></li></ul></li>
<li><a href="Backpropagation" title="Backpropagation">Backpropagation</a></li>
<li><a href="Attention_(machine_learning)" title="Attention (machine learning)">Attention</a></li>
<li><a href="Convolution" title="Convolution">Convolution</a></li>
<li><a href="Normalization_(machine_learning)" title="Normalization (machine learning)">Normalization</a>
<ul><li><a href="Batch_normalization" title="Batch normalization">Batchnorm</a></li></ul></li>
<li><a href="Activation_function" title="Activation function">Activation</a>
<ul><li><a href="Softmax_function" title="Softmax function">Softmax</a></li>
<li><a href="Sigmoid_function" title="Sigmoid function">Sigmoid</a></li>
<li><a href="Rectifier_(neural_networks)" title="Rectifier (neural networks)">Rectifier</a></li></ul></li>
<li><a href="Gating_mechanism" title="Gating mechanism">Gating</a></li>
<li><a href="Weight_initialization" title="Weight initialization">Weight initialization</a></li>
<li><a href="Regularization_(mathematics)" title="Regularization (mathematics)">Regularization</a></li>
<li><a href="Training%2C_validation%2C_and_test_data_sets" title="Training, validation, and test data sets">Datasets</a>
<ul><li><a href="Data_augmentation" title="Data augmentation">Augmentation</a></li></ul></li>
<li><a href="Prompt_engineering" title="Prompt engineering">Prompt engineering</a></li>
<li><a href="Reinforcement_learning" title="Reinforcement learning">Reinforcement learning</a>
<ul><li><a href="Q-learning" title="Q-learning">Q-learning</a></li>
<li><a href="State%E2%80%93action%E2%80%93reward%E2%80%93state%E2%80%93action" title="State–action–reward–state–action">SARSA</a></li>
<li><a href="Imitation_learning" title="Imitation learning">Imitation</a></li>
<li><a href="Policy_gradient_method" title="Policy gradient method">Policy gradient</a></li></ul></li>
<li><a href="Diffusion_process" title="Diffusion process">Diffusion</a></li>
<li><a href="Latent_diffusion_model" title="Latent diffusion model">Latent diffusion model</a></li>
<li><a href="Autoregressive_model" title="Autoregressive model">Autoregression</a></li>
<li><a href="Retrieval-augmented_generation" title="Retrieval-augmented generation">RAG</a></li>
<li><a href="Uncanny_valley" title="Uncanny valley">Uncanny valley</a></li>
<li><a href="Reinforcement_learning_from_human_feedback" title="Reinforcement learning from human feedback">RLHF</a></li>
<li><a href="Self-supervised_learning" title="Self-supervised learning">Self-supervised learning</a></li>
<li><a href="Reflection_(artificial_intelligence)" class="mw-redirect" title="Reflection (artificial intelligence)">Reflection</a></li>
<li><a href="Recursive_self-improvement" title="Recursive self-improvement">Recursive self-improvement</a></li>
<li><a href="Hallucination_(artificial_intelligence)" title="Hallucination (artificial intelligence)">Hallucination</a></li>
<li><a href="Word_embedding" title="Word embedding">Word embedding</a></li>
<li><a href="Vibe_coding" title="Vibe coding">Vibe coding</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Applications</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Machine_learning" title="Machine learning">Machine learning</a>
<ul><li><a href="Prompt_engineering#In-context_learning" title="Prompt engineering">In-context learning</a></li></ul></li>
<li><a href="Neural_network_(machine_learning)" title="Neural network (machine learning)">Artificial neural network</a>
<ul><li><a href="Deep_learning" title="Deep learning">Deep learning</a></li></ul></li>
<li><a href="Language_model" title="Language model">Language model</a>
<ul><li><a href="Large_language_model" title="Large language model">Large language model</a></li>
<li><a href="Neural_machine_translation" title="Neural machine translation">NMT</a></li></ul></li>
<li><a href="Reasoning_language_model" title="Reasoning language model">Reasoning language model</a></li>
<li><a href="Model_Context_Protocol" title="Model Context Protocol">Model Context Protocol</a></li>
<li><a href="Intelligent_agent" title="Intelligent agent">Intelligent agent</a></li>
<li><a href="Artificial_human_companion" title="Artificial human companion">Artificial human companion</a></li>
<li><a href="Humanity's_Last_Exam" title="Humanity's Last Exam">Humanity's Last Exam</a></li>
<li><a href="Artificial_general_intelligence" title="Artificial general intelligence">Artificial general intelligence (AGI)</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Implementations</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Audio–visual</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="AlexNet" title="AlexNet">AlexNet</a></li>
<li><a href="WaveNet" title="WaveNet">WaveNet</a></li>
<li><a href="Human_image_synthesis" title="Human image synthesis">Human image synthesis</a></li>
<li><a href="Handwriting_recognition" title="Handwriting recognition">HWR</a></li>
<li><a href="Optical_character_recognition" title="Optical character recognition">OCR</a></li>
<li><a href="Computer_vision" title="Computer vision">Computer vision</a></li>
<li><a href="Deep_learning_speech_synthesis" title="Deep learning speech synthesis">Speech synthesis</a>
<ul><li><a href="15.ai" title="15.ai">15.ai</a></li>
<li><a href="ElevenLabs" title="ElevenLabs">ElevenLabs</a></li></ul></li>
<li><a href="Speech_recognition" title="Speech recognition">Speech recognition</a>
<ul><li><a href="Whisper_(speech_recognition_system)" title="Whisper (speech recognition system)">Whisper</a></li></ul></li>
<li><a href="Facial_recognition_system" title="Facial recognition system">Facial recognition</a></li>
<li><a href="AlphaFold" title="AlphaFold">AlphaFold</a></li>
<li><a href="Text-to-image_model" title="Text-to-image model">Text-to-image models</a>
<ul><li><a href="Aurora_(text-to-image_model)" class="mw-redirect" title="Aurora (text-to-image model)">Aurora</a></li>
<li><a href="DALL-E" title="DALL-E">DALL-E</a></li>
<li><a href="Adobe_Firefly" title="Adobe Firefly">Firefly</a></li>
<li><a href="Flux_(text-to-image_model)" title="Flux (text-to-image model)">Flux</a></li>
<li><a href="Ideogram_(text-to-image_model)" title="Ideogram (text-to-image model)">Ideogram</a></li>
<li><a href="Imagen_(text-to-image_model)" title="Imagen (text-to-image model)">Imagen</a></li>
<li><a href="Midjourney" title="Midjourney">Midjourney</a></li>
<li><a href="Recraft" title="Recraft">Recraft</a></li>
<li><a href="Stable_Diffusion" title="Stable Diffusion">Stable Diffusion</a></li></ul></li>
<li><a href="Text-to-video_model" title="Text-to-video model">Text-to-video models</a>
<ul><li><a href="Dream_Machine_(text-to-video_model)" title="Dream Machine (text-to-video model)">Dream Machine</a></li>
<li><a href="Runway_(company)#Services_and_technologies" title="Runway (company)">Runway Gen</a></li>
<li><a href="MiniMax_(company)#Hailuo_AI" title="MiniMax (company)">Hailuo AI</a></li>
<li><a href="Kling_(text-to-video_model)" class="mw-redirect" title="Kling (text-to-video model)">Kling</a></li>
<li><a href="Sora_(text-to-video_model)" title="Sora (text-to-video model)">Sora</a></li>
<li><a href="Veo_(text-to-video_model)" title="Veo (text-to-video model)">Veo</a></li></ul></li>
<li><a href="Music_and_artificial_intelligence" title="Music and artificial intelligence">Music generation</a>
<ul><li><a href="Riffusion" title="Riffusion">Riffusion</a></li>
<li><a href="Suno_AI" title="Suno AI">Suno AI</a></li>
<li><a href="Udio" title="Udio">Udio</a></li></ul></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Text</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Word2vec" title="Word2vec">Word2vec</a></li>
<li><a href="Seq2seq" title="Seq2seq">Seq2seq</a></li>
<li><a href="GloVe" title="GloVe">GloVe</a></li>
<li><a href="BERT_(language_model)" title="BERT (language model)">BERT</a></li>
<li><a href="T5_(language_model)" title="T5 (language model)">T5</a></li>
<li><a href="Llama_(language_model)" title="Llama (language model)">Llama</a></li>
<li><a href="Chinchilla_(language_model)" title="Chinchilla (language model)">Chinchilla AI</a></li>
<li><a href="PaLM" title="PaLM">PaLM</a></li>
<li><a href="Generative_pre-trained_transformer" title="Generative pre-trained transformer">GPT</a>
<ul><li><a href="GPT-1" title="GPT-1">1</a></li>
<li><a href="GPT-2" title="GPT-2">2</a></li>
<li><a href="GPT-3" title="GPT-3">3</a></li>
<li><a href="GPT-J" title="GPT-J">J</a></li>
<li><a href="ChatGPT" title="ChatGPT">ChatGPT</a></li>
<li><a href="GPT-4" title="GPT-4">4</a></li>
<li><a href="GPT-4o" title="GPT-4o">4o</a></li>
<li><a href="OpenAI_o1" title="OpenAI o1">o1</a></li>
<li><a href="OpenAI_o3" title="OpenAI o3">o3</a></li>
<li><a href="GPT-4.5" title="GPT-4.5">4.5</a></li>
<li><a href="GPT-4.1" title="GPT-4.1">4.1</a></li>
<li><a href="OpenAI_o4-mini" title="OpenAI o4-mini">o4-mini</a></li>
<li><a href="GPT-5" title="GPT-5">5</a></li></ul></li>
<li><a href="Claude_(language_model)" title="Claude (language model)">Claude</a></li>
<li><a href="Gemini_(language_model)" title="Gemini (language model)">Gemini</a>
<ul><li><a href="Gemini_(chatbot)" title="Gemini (chatbot)">chatbot</a></li></ul></li>
<li><a href="Grok_(chatbot)" title="Grok (chatbot)">Grok</a></li>
<li><a href="LaMDA" title="LaMDA">LaMDA</a></li>
<li><a href="BLOOM_(language_model)" title="BLOOM (language model)">BLOOM</a></li>
<li><a href="DBRX" title="DBRX">DBRX</a></li>
<li><a href="Project_Debater" title="Project Debater">Project Debater</a></li>
<li><a href="IBM_Watson" title="IBM Watson">IBM Watson</a></li>
<li><a href="IBM_Watsonx" title="IBM Watsonx">IBM Watsonx</a></li>
<li><a href="IBM_Granite" title="IBM Granite">Granite</a></li>
<li><a href="Huawei_PanGu" title="Huawei PanGu">PanGu-Σ</a></li>
<li><a href="DeepSeek_(chatbot)" title="DeepSeek (chatbot)">DeepSeek</a></li>
<li><a href="Qwen" title="Qwen">Qwen</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Decisional</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="AlphaGo" title="AlphaGo">AlphaGo</a></li>
<li><a href="AlphaZero" title="AlphaZero">AlphaZero</a></li>
<li><a href="OpenAI_Five" title="OpenAI Five">OpenAI Five</a></li>
<li><a href="Self-driving_car" title="Self-driving car">Self-driving car</a></li>
<li><a href="MuZero" title="MuZero">MuZero</a></li>
<li><a href="Action_selection" title="Action selection">Action selection</a>
<ul><li><a href="AutoGPT" title="AutoGPT">AutoGPT</a></li></ul></li>
<li><a href="Robot_control" title="Robot control">Robot control</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">People</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Alan_Turing" title="Alan Turing">Alan Turing</a></li>
<li><a href="Warren_Sturgis_McCulloch" title="Warren Sturgis McCulloch">Warren Sturgis McCulloch</a></li>
<li><a href="Walter_Pitts" title="Walter Pitts">Walter Pitts</a></li>
<li><a href="John_von_Neumann" title="John von Neumann">John von Neumann</a></li>
<li><a href="Claude_Shannon" title="Claude Shannon">Claude Shannon</a></li>
<li><a href="Shun'ichi_Amari" title="Shun'ichi Amari">Shun'ichi Amari</a></li>
<li><a href="Kunihiko_Fukushima" title="Kunihiko Fukushima">Kunihiko Fukushima</a></li>
<li><a href="Takeo_Kanade" title="Takeo Kanade">Takeo Kanade</a></li>
<li><a href="Marvin_Minsky" title="Marvin Minsky">Marvin Minsky</a></li>
<li><a href="John_McCarthy_(computer_scientist)" title="John McCarthy (computer scientist)">John McCarthy</a></li>
<li><a href="Nathaniel_Rochester_(computer_scientist)" title="Nathaniel Rochester (computer scientist)">Nathaniel Rochester</a></li>
<li><a href="Allen_Newell" title="Allen Newell">Allen Newell</a></li>
<li><a href="Cliff_Shaw" title="Cliff Shaw">Cliff Shaw</a></li>
<li><a href="Herbert_A._Simon" title="Herbert A. Simon">Herbert A. Simon</a></li>
<li><a href="Oliver_Selfridge" title="Oliver Selfridge">Oliver Selfridge</a></li>
<li><a href="Frank_Rosenblatt" title="Frank Rosenblatt">Frank Rosenblatt</a></li>
<li><a href="Bernard_Widrow" title="Bernard Widrow">Bernard Widrow</a></li>
<li><a href="Joseph_Weizenbaum" title="Joseph Weizenbaum">Joseph Weizenbaum</a></li>
<li><a href="Seymour_Papert" title="Seymour Papert">Seymour Papert</a></li>
<li><a href="Seppo_Linnainmaa" title="Seppo Linnainmaa">Seppo Linnainmaa</a></li>
<li><a href="Paul_Werbos" title="Paul Werbos">Paul Werbos</a></li>
<li><a href="Geoffrey_Hinton" title="Geoffrey Hinton">Geoffrey Hinton</a></li>
<li><a href="John_Hopfield" title="John Hopfield">John Hopfield</a></li>
<li><a href="J%C3%BCrgen_Schmidhuber" title="Jürgen Schmidhuber">Jürgen Schmidhuber</a></li>
<li><a href="Yann_LeCun" title="Yann LeCun">Yann LeCun</a></li>
<li><a href="Yoshua_Bengio" title="Yoshua Bengio">Yoshua Bengio</a></li>
<li><a href="Lotfi_A._Zadeh" title="Lotfi A. Zadeh">Lotfi A. Zadeh</a></li>
<li><a href="Stephen_Grossberg" title="Stephen Grossberg">Stephen Grossberg</a></li>
<li><a href="Alex_Graves_(computer_scientist)" title="Alex Graves (computer scientist)">Alex Graves</a></li>
<li><a href="James_Goodnight" title="James Goodnight">James Goodnight</a></li>
<li><a href="Andrew_Ng" title="Andrew Ng">Andrew Ng</a></li>
<li><a href="Fei-Fei_Li" title="Fei-Fei Li">Fei-Fei Li</a></li>
<li><a href="Ilya_Sutskever" title="Ilya Sutskever">Ilya Sutskever</a></li>
<li><a href="Alex_Krizhevsky" title="Alex Krizhevsky">Alex Krizhevsky</a></li>
<li><a href="Ian_Goodfellow" title="Ian Goodfellow">Ian Goodfellow</a></li>
<li><a href="Demis_Hassabis" title="Demis Hassabis">Demis Hassabis</a></li>
<li><a href="David_Silver_(computer_scientist)" title="David Silver (computer scientist)">David Silver</a></li>
<li><a href="Andrej_Karpathy" title="Andrej Karpathy">Andrej Karpathy</a></li>
<li><a href="Ashish_Vaswani" title="Ashish Vaswani">Ashish Vaswani</a></li>
<li><a href="Noam_Shazeer" title="Noam Shazeer">Noam Shazeer</a></li>
<li><a href="Aidan_Gomez" title="Aidan Gomez">Aidan Gomez</a></li>
<li><a href="Mustafa_Suleyman" title="Mustafa Suleyman">Mustafa Suleyman</a></li>
<li><a href="Fran%C3%A7ois_Chollet" title="François Chollet">François Chollet</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Architectures</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Neural_Turing_machine" title="Neural Turing machine">Neural Turing machine</a></li>
<li><a href="Differentiable_neural_computer" title="Differentiable neural computer">Differentiable neural computer</a></li>
<li><a href="Transformer_(deep_learning_architecture)" title="Transformer (deep learning architecture)">Transformer</a>
<ul><li><a href="Vision_transformer" title="Vision transformer">Vision transformer (ViT)</a></li></ul></li>
<li><a href="Recurrent_neural_network" title="Recurrent neural network">Recurrent neural network (RNN)</a></li>
<li><a href="Long_short-term_memory" title="Long short-term memory">Long short-term memory (LSTM)</a></li>
<li><a href="Gated_recurrent_unit" title="Gated recurrent unit">Gated recurrent unit (GRU)</a></li>
<li><a href="Echo_state_network" title="Echo state network">Echo state network</a></li>
<li><a href="Multilayer_perceptron" title="Multilayer perceptron">Multilayer perceptron (MLP)</a></li>
<li><a href="Convolutional_neural_network" title="Convolutional neural network">Convolutional neural network (CNN)</a></li>
<li><a href="Residual_neural_network" title="Residual neural network">Residual neural network (RNN)</a></li>
<li><a href="Highway_network" title="Highway network">Highway network</a></li>
<li><a href="Mamba_(deep_learning_architecture)" title="Mamba (deep learning architecture)">Mamba</a></li>
<li><a href="Autoencoder" title="Autoencoder">Autoencoder</a></li>
<li><a href="Variational_autoencoder" title="Variational autoencoder">Variational autoencoder (VAE)</a></li>
<li><a href="Generative_adversarial_network" title="Generative adversarial network">Generative adversarial network (GAN)</a></li>
<li><a href="Graph_neural_network" title="Graph neural network">Graph neural network (GNN)</a></li></ul>
</div></td></tr><tr><td class="navbox-abovebelow" colspan="2"><div>
<ul><li><span class="noviewer" typeof="mw:File"><span title="Category"></span></span> Category</li></ul>
</div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-06-25" href="https://en.wikipedia.org/wiki/?title=Adversarial_machine_learning&oldid=1297254329">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>