Towards Standardized and Accurate Evaluation of the Robustness of Image Classifiers against Adversarial Attacks



Francesco Croce (University of Tuebingen)

Francesco Croce is a Ph.D. student in the Machine Learning group at the University of Tuebingen, Germany. He received his BS in Mathematics for Finance and Insurance and his MS in Mathematics from the University of Torino, Italy. His research focuses on adversarial attacks in different threat models and provable robustness.



Short Abstract: It is well known that image classifiers are vulnerable to adversarial perturbations, and many defenses have been suggested to mitigate this phenomenon.However, testing the effectiveness of a defense is not straightforward.We propose a protocol for standardized and accurate evaluation of a large class of adversarial defenses, which allows to benchmark and track the progress of adversarial robustness in several threat models.