Saved in:
Bibliographic Details
Main Authors: Ciosek, Kamil, Petrov, Aleksandr V., Felicioni, Nicolò, Palla, Konstantina
Format: Preprint
Published: 2026
Subjects:
Online Access:https://arxiv.org/abs/2605.14868
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918501691686912
author Ciosek, Kamil
Petrov, Aleksandr V.
Felicioni, Nicolò
Palla, Konstantina
author_facet Ciosek, Kamil
Petrov, Aleksandr V.
Felicioni, Nicolò
Palla, Konstantina
contents Generating adversarial examples at scale is a core primitive for robustness evaluation, adversarial training, and red-teaming, yet even "fast" attacks such as FGSM remain throughput-limited by the cost of a backward pass. We introduce a family of attacks that eliminates the backward pass by predicting the input gradient from forward-pass hidden states via a lightweight linear regression. The approach is motivated by a kernel view of neural networks and is exact in the Neural Tangent Kernel regime, while remaining effective for practical finite-width models. Empirically, our methods recover much of FGSM's attack performance while using only a small fraction of the time, corresponding to a $532\%$ increase in throughput. These results suggest gradient prediction as a simple and general route to significantly faster adversarial generation under realistic wall-clock constraints.
format Preprint
id arxiv_https___arxiv_org_abs_2605_14868
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Fast Adversarial Attacks with Gradient Prediction
Ciosek, Kamil
Petrov, Aleksandr V.
Felicioni, Nicolò
Palla, Konstantina
Machine Learning
Generating adversarial examples at scale is a core primitive for robustness evaluation, adversarial training, and red-teaming, yet even "fast" attacks such as FGSM remain throughput-limited by the cost of a backward pass. We introduce a family of attacks that eliminates the backward pass by predicting the input gradient from forward-pass hidden states via a lightweight linear regression. The approach is motivated by a kernel view of neural networks and is exact in the Neural Tangent Kernel regime, while remaining effective for practical finite-width models. Empirically, our methods recover much of FGSM's attack performance while using only a small fraction of the time, corresponding to a $532\%$ increase in throughput. These results suggest gradient prediction as a simple and general route to significantly faster adversarial generation under realistic wall-clock constraints.
title Fast Adversarial Attacks with Gradient Prediction
topic Machine Learning
url https://arxiv.org/abs/2605.14868