TruthSeekers

Rabbit hole · 3 connected questions

How do choices and adaptivity in empirical attacks versus formal certification create a persistent evaluation gap in claimed model robustness?

How these converge

All three topics are about how we judge whether a model is robust to adversarial perturbations. PGD is the common, practical baseline for generating attacks but is highly sensitive to choices (loss, norm, step size, initialization). Adaptive PGD variants deliberately change those choices to find much stronger failures, showing that a non-adaptive PGD can give a misleading picture of robustness. Certified defenses sit on the other side: they provide attack-independent guarantees but make modeling, scalability, or tightness tradeoffs. Together they point to a single concrete problem: empirical robustness claims depend on which attacks and hyperparameters were tried, while certificates avoid that fragility at the cost of restricted threat models or loose bounds—so evaluating defenses requires understanding both adaptive attack capability and certification limits.

Where these converge

The chain

Keep going: open any topic above to find its own related questions.