TruthSeekers

Rabbit hole · 6 connected questions

Do robustness methods and evaluations for adversarial examples actually generalize beyond the specific threat models, attacks, and data used to design them?

How these converge

Each topic addresses the same concrete gap between defended/evaluated settings and real-world threats: attack algorithms (PGD) and evaluation choices operationalize a narrow threat model; adversarial training and certified defenses are different remedies targeted to those models; transferability and adaptive attacks show routes that bypass those remedies; and robustness–accuracy tradeoffs determine practical viability. The core issue is whether claimed robustness holds when attackers, data, or models deviate from the original assumptions.

Where these converge

The chain

Keep going: open any topic above to find its own related questions.