Lattice Climber Attack: Adversarial attacks for randomized mixtures of classifiers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gnecco-Heredia, Lucas, Negrevergne, Benjamin, Chevaleyre, Yann
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911002274037760
author Gnecco-Heredia, Lucas
Negrevergne, Benjamin
Chevaleyre, Yann
author_facet Gnecco-Heredia, Lucas
Negrevergne, Benjamin
Chevaleyre, Yann
contents Finite mixtures of classifiers (a.k.a. randomized ensembles) have been proposed as a way to improve robustness against adversarial attacks. However, existing attacks have been shown to not suit this kind of classifier. In this paper, we discuss the problem of attacking a mixture in a principled way and introduce two desirable properties of attacks based on a geometrical analysis of the problem (effectiveness and maximality). We then show that existing attacks do not meet both of these properties. Finally, we introduce a new attack called {\em lattice climber attack} with theoretical guarantees in the binary linear setting, and demonstrate its performance by conducting experiments on synthetic and real datasets.
format Preprint
id arxiv_https___arxiv_org_abs_2506_10888
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Lattice Climber Attack: Adversarial attacks for randomized mixtures of classifiers
Gnecco-Heredia, Lucas
Negrevergne, Benjamin
Chevaleyre, Yann
Machine Learning
Finite mixtures of classifiers (a.k.a. randomized ensembles) have been proposed as a way to improve robustness against adversarial attacks. However, existing attacks have been shown to not suit this kind of classifier. In this paper, we discuss the problem of attacking a mixture in a principled way and introduce two desirable properties of attacks based on a geometrical analysis of the problem (effectiveness and maximality). We then show that existing attacks do not meet both of these properties. Finally, we introduce a new attack called {\em lattice climber attack} with theoretical guarantees in the binary linear setting, and demonstrate its performance by conducting experiments on synthetic and real datasets.
title Lattice Climber Attack: Adversarial attacks for randomized mixtures of classifiers
topic Machine Learning
url https://arxiv.org/abs/2506.10888