Current research on defending against adversarial examples focuses primarily on achieving robustness against a single attack type such as $\ell_2$ or $\ell_{\infty}$-bounded attacks. However, the space of possible perturbations is much larger and currently cannot be modeled by a single attack type. The discrepancy between the focus of current defenses and the space of attacks of interest calls to question the practicality of existing defenses and the reliability of their evaluation. In this position paper, we argue that the research community should look beyond single attack robustness, and we draw attention to three potential directions involving robustness against multiple attacks: simultaneous multiattack robustness, unforeseen attack robustness, and a newly defined problem setting which we call continual adaptive robustness. We provide a unified framework which rigorously defines these problem settings, synthesize existing research in these fields, and outline open directions. We hope that our position paper inspires more research in simultaneous multiattack, unforeseen attack, and continual adaptive robustness.
翻译:当前针对对抗性样本防御的研究主要集中于实现对单一攻击类型(如$\ell_2$或$\ell_{\infty}$有界攻击)的鲁棒性。然而,可能的扰动空间远大于此,且目前无法通过单一攻击类型来建模。现有防御研究的聚焦点与所关注攻击空间之间的差异,引发了人们对现有防御的实用性及其评估可靠性的质疑。在本立场论文中,我们主张研究社区应超越单一攻击鲁棒性的视角,并关注涉及多攻击鲁棒性的三个潜在方向:同时多攻击鲁棒性、未知攻击鲁棒性,以及我们新定义的问题设置——“持续自适应鲁棒性”。我们提供了一个统一框架,严格定义了这些问题设置,整合了这些领域的现有研究,并指出了开放研究方向。我们希望本立场论文能激励更多关于同时多攻击、未知攻击和持续自适应鲁棒性的研究。