Adversarial Attacks on ML Defense Models Competition
Yinpeng Dong,Qi-An Fu,Xiao Yang,Wenzhao Xiang,Tianyu Pang,Hang Su,Jun Zhu,Jiayu Tang,Yuefeng Chen,XiaoFeng Mao,Yuan He,Hui Xue,Chao Li,Ye Liu,Qilong Zhang,Lianli Gao,Yunrui Yu,Xitong Gao,Zhe Zhao,Daquan Lin,Jiadong Lin,Chuanbiao Song,Zihao Wang,Zhennan Wu,Yang Guo,Jiequan Cui,Xiaogang Xu,Pengguang Chen
DOI: https://doi.org/10.48550/arXiv.2110.08042
2021-10-15
Abstract:Due to the vulnerability of deep neural networks (DNNs) to adversarial examples, a large number of defense techniques have been proposed to alleviate this problem in recent years. However, the progress of building more robust models is usually hampered by the incomplete or incorrect robustness evaluation. To accelerate the research on reliable evaluation of adversarial robustness of the current defense models in image classification, the TSAIL group at Tsinghua University and the Alibaba Security group organized this competition along with a CVPR 2021 workshop on adversarial machine learning (<a class="link-external link-https" href="https://aisecure-workshop.github.io/amlcvpr2021/" rel="external noopener nofollow">this https URL</a>). The purpose of this competition is to motivate novel attack algorithms to evaluate adversarial robustness more effectively and reliably. The participants were encouraged to develop stronger white-box attack algorithms to find the worst-case robustness of different defenses. This competition was conducted on an adversarial robustness evaluation platform -- ARES (<a class="link-external link-https" href="https://github.com/thu-ml/ares" rel="external noopener nofollow">this https URL</a>), and is held on the TianChi platform (<a class="link-external link-https" href="https://tianchi.aliyun.com/competition/entrance/531847/introduction" rel="external noopener nofollow">this https URL</a>) as one of the series of AI Security Challengers Program. After the competition, we summarized the results and established a new adversarial robustness benchmark at <a class="link-external link-https" href="https://ml.cs.tsinghua.edu.cn/ares-bench/" rel="external noopener nofollow">this https URL</a>, which allows users to upload adversarial attack algorithms and defense models for evaluation.
Computer Vision and Pattern Recognition,Artificial Intelligence,Cryptography and Security,Machine Learning