English

Performance Evaluation of Adversarial Attacks: Discrepancies and Solutions

Machine Learning 2021-04-23 v1 Cryptography and Security

Abstract

Recently, adversarial attack methods have been developed to challenge the robustness of machine learning models. However, mainstream evaluation criteria experience limitations, even yielding discrepancies among results under different settings. By examining various attack algorithms, including gradient-based and query-based attacks, we notice the lack of a consensus on a uniform standard for unbiased performance evaluation. Accordingly, we propose a Piece-wise Sampling Curving (PSC) toolkit to effectively address the aforementioned discrepancy, by generating a comprehensive comparison among adversaries in a given range. In addition, the PSC toolkit offers options for balancing the computational cost and evaluation effectiveness. Experimental results demonstrate our PSC toolkit presents comprehensive comparisons of attack algorithms, significantly reducing discrepancies in practice.

Keywords

Cite

@article{arxiv.2104.11103,
  title  = {Performance Evaluation of Adversarial Attacks: Discrepancies and Solutions},
  author = {Jing Wu and Mingyi Zhou and Ce Zhu and Yipeng Liu and Mehrtash Harandi and Li Li},
  journal= {arXiv preprint arXiv:2104.11103},
  year   = {2021}
}
R2 v1 2026-06-24T01:26:02.849Z