2022
Indicators of Attack Failure: Debugging and Improving Optimization of Adversarial Examples
NeurIPS 2022accept
Evaluating robustness of machine-learning models to adversarial examples is a challenging problem. Many defenses have been shown to provide a false sense of robustness by causing gradient-based attacks to fail, and they have been broken under more rigorous evaluations. Although guidelines and best p…