We evaluate the robustness of Adversarial Logit Pairing, a recently proposed defense against adversarial examples. We find that a network trained with Adversarial Logit Pairing achieves 0.6% accuracy in the threat model in which the defense is considered. We provide a brief overview of the defense and the threat models/claims considered, as well as a discussion of the methodology and results of our attack, which may offer insights into the reasons underlying the vulnerability of ALP to adversarial attack.
@article{arxiv.1807.10272,
title = {Evaluating and Understanding the Robustness of Adversarial Logit Pairing},
author = {Logan Engstrom and Andrew Ilyas and Anish Athalye},
journal= {arXiv preprint arXiv:1807.10272},
year = {2018}
}
Comments
NeurIPS SECML 2018. Source code at https://github.com/labsix/adversarial-logit-pairing-analysis