Rabbit hole · 6 connected questions
Do robustness methods and evaluations for adversarial examples actually generalize beyond the specific threat models, attacks, and data used to design them?
How these converge
Each topic addresses the same concrete gap between defended/evaluated settings and real-world threats: attack algorithms (PGD) and evaluation choices operationalize a narrow threat model; adversarial training and certified defenses are different remedies targeted to those models; transferability and adaptive attacks show routes that bypass those remedies; and robustness–accuracy tradeoffs determine practical viability. The core issue is whether claimed robustness holds when attackers, data, or models deviate from the original assumptions.
Where these converge
Evaluation–threat-model mismatch undermines claimed robustness
PGD-based evaluations and many defenses depend on specific loss choices, norms, and budgets; when attackers use different objectives, constraint handling, or adaptivity, apparent robustness often fails. This connects limits of PGD as a universal test to the need for defense-aware evaluation.
Provable guarantees versus empirical, attack-dependent defenses
Certified defenses give attack-independent certificates for a specified threat model but trade off tightness and scalability. Empirical defenses like adversarial training can be effective against known attacks yet remain vulnerable when evaluation gaps are exploited.
Transferability and attacker knowledge broaden the threat beyond local defenses
Adversarial examples can transfer between models, so defenses validated only in white-box or single-model settings can be bypassed by substitute-model or black-box strategies, widening the attacker capabilities defenders must consider.
Robustness claims hinge on data, model class, and utility tradeoffs
Observed robustness–accuracy tradeoffs mean defenses that improve worst-case robustness may hurt clean accuracy or generalization; whether a defense is useful depends on dataset geometry, model class, and deployment requirements.
The chain
Keep going: open any topic above to find its own related questions.