Pith. sign in

REVIEW 2 cited by

Gradient Masking Causes CLEVER to Overestimate Adversarial Perturbation Size

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1804.07870 v1 pith:5XZDUX7Z submitted 2018-04-21 cs.LG stat.ML

classification cs.LGstat.ML
keywords boundattackcleverperturbationsizeadversarialalgorithmscauses
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

A key problem in research on adversarial examples is that vulnerability to adversarial examples is usually measured by running attack algorithms. Because the attack algorithms are not optimal, the attack algorithms are prone to overestimating the size of perturbation needed to fool the target model. In other words, the attack-based methodology provides an upper-bound on the size of a perturbation that will fool the model, but security guarantees require a lower bound. CLEVER is a proposed scoring method to estimate a lower bound. Unfortunately, an estimate of a bound is not a bound. In this report, we show that gradient masking, a common problem that causes attack methodologies to provide only a very loose upper bound, causes CLEVER to overestimate the size of perturbation needed to fool the model. In other words, CLEVER does not resolve the key problem with the attack-based methodology, because it fails to provide a lower bound.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Testing Robustness Against Unforeseen Adversaries

    cs.LG 2019-08 conditional novelty 8.0 of 10

    ImageNet-UA, a six-attack benchmark with four new attacks, shows L-infinity robustness does not transfer to unforeseen distortions and that L2 training and AugMix generalize better.

  2. Theoretical Analysis of Relative Errors in Gradient Computations for Adversarial Attacks with CE Loss

    cs.LG 2025-07 conditional novelty 4.0 of 10

    T-MIFPE adaptively rescales logits with a theoretically motivated t* per attack phase to reduce floating-point gradient errors, edging out MIFPE in PGD robustness evaluation.

Pith tools