arXiv · 2408.06166
Detecting adversarial attacks on random samples
Abstract
This paper studies the problem of detecting adversarial perturbations in a sequence of observations. Given a data sample $X_1, \ldots, X_n$ drawn from a standard normal distribution, an adversary, after observing the sample, can perturb each observation by a fixed magnitude or leave it unchanged. We explore the relationship between the perturbation magnitude, the sparsity of the perturbation, and the detectability of the adversary's actions, establishing precise thresholds for when detection becomes impossible.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Gleb Smirnov. 2024-08-12. Detecting adversarial attacks on random samples. https://arxiv.org/abs/2408.06166
Cite the original work for its findings. Save a collection to share your selection of sources.