PGD-Imp: Rethinking and Unleashing Potential of Classic PGD with Dual Strategies for Imperceptible Adversarial Attacks

AI-generated keywords: Imperceptible Adversarial Attacks Projected Gradient Descent (PGD) Dynamic Step Size Adaptive Early Stop ResNet-50

AI-generated Key Points

The license of the paper does not allow us to build upon its content and the key points are generated using the paper metadata rather than the full article.

  • Surge in research interest towards imperceptible adversarial attacks
  • Existing approaches often involve complex external modules or additional loss terms
  • Recent study challenges the necessity of elaborate designs
  • Authors propose novel perspective on imperceptible attacks using Projected Gradient Descent (PGD)
  • Introduce Dynamic Step Size strategy for minimal attack cost towards decision boundary
  • Implement Adaptive Early Stop strategy to reduce excessive strength of perturbations
  • PGD-Imp attack demonstrates significant advancements in imperceptible adversarial attacks
  • Achieves remarkable results in untargeted attacks against ResNet-50 model
  • Shows superior performance with reduced running time compared to existing methods
Also access our AI generated: Comprehensive summary, Lay summary, Blog-like article; or ask questions about this paper to our AI assistant.

Authors: Jin Li, Zitong Yu, Ziqiang He, Z. Jane Wang, Xiangui Kang

Abstract: Imperceptible adversarial attacks have recently attracted increasing research interests. Existing methods typically incorporate external modules or loss terms other than a simple $l_p$-norm into the attack process to achieve imperceptibility, while we argue that such additional designs may not be necessary. In this paper, we rethink the essence of imperceptible attacks and propose two simple yet effective strategies to unleash the potential of PGD, the common and classical attack, for imperceptibility from an optimization perspective. Specifically, the Dynamic Step Size is introduced to find the optimal solution with minimal attack cost towards the decision boundary of the attacked model, and the Adaptive Early Stop strategy is adopted to reduce the redundant strength of adversarial perturbations to the minimum level. The proposed PGD-Imperceptible (PGD-Imp) attack achieves state-of-the-art results in imperceptible adversarial attacks for both untargeted and targeted scenarios. When performing untargeted attacks against ResNet-50, PGD-Imp attains 100$\%$ (+0.3$\%$) ASR, 0.89 (-1.76) $l_2$ distance, and 52.93 (+9.2) PSNR with 57s (-371s) running time, significantly outperforming existing methods.

Submitted to arXiv on 15 Dec. 2024

Ask questions about this paper to our AI assistant

You can also chat with multiple papers at once here.

The license of the paper does not allow us to build upon its content and the AI assistant only knows about the paper metadata rather than the full article.

AI assistant instructions?

Results of the summarizing process for the arXiv paper: 2412.11168v1

This paper's license doesn't allow us to build upon its content and the summarizing process is here made with the paper's metadata rather than the article.

In the realm of imperceptible adversarial attacks, there has been a surge in research interest towards developing methods that can effectively deceive machine learning models without being easily detected by human observers. Existing approaches often involve complex external modules or incorporate additional loss terms beyond simple $l_p$-norm to achieve imperceptibility. However, a recent study challenges the necessity of such elaborate designs. In this paper titled "PGD-Imp: Rethinking and Unleashing Potential of Classic PGD with Dual Strategies for Imperceptible Adversarial Attacks," authors Jin Li, Zitong Yu, Ziqiang He, Z. Jane Wang, and Xiangui Kang propose a novel perspective on imperceptible attacks. The authors introduce two straightforward yet powerful strategies to enhance the potential of Projected Gradient Descent (PGD), a widely used classical attack method, for achieving imperceptibility from an optimization standpoint. The first strategy involves the implementation of Dynamic Step Size, which aims to identify an optimal solution with minimal attack cost towards the decision boundary of the targeted model. By dynamically adjusting the step size during the optimization process, this approach enhances efficiency and effectiveness in generating imperceptible adversarial perturbations. The second strategy proposed by the authors is Adaptive Early Stop, which focuses on reducing the excessive strength of adversarial perturbations to minimize their impact on input data. By strategically halting the optimization process when reaching a certain threshold level of perturbation strength, this strategy helps generate more subtle and less noticeable adversarial examples. Through these innovative strategies collectively known as PGD-Imperceptible (PGD-Imp) attack, significant advancements are demonstrated in imperceptible adversarial attacks for both untargeted and targeted scenarios. Specifically, when conducting untargeted attacks against the ResNet-50 model, PGD-Imp achieves remarkable results including 100% (+0.3%) Attack Success Rate (ASR), 0.89 (-1.76) $l_2$ distance from original inputs, and 52.93 (+9.2) Peak Signal-to-Noise Ratio (PSNR). Moreover, compared to existing methods, PGD-Imp showcases superior performance with a reduced running time of 57 seconds (compared to -371 seconds). Overall, this study not only redefines our understanding of imperceptible attacks but also presents practical and efficient strategies that leverage classic techniques like PGD to achieve state-of-the-art results in deceiving machine learning models while maintaining visual indistinguishability to human observers.
Created on 19 Aug. 2026

Assess the quality of the AI-generated content by voting

Score: 0

Why do we need votes?

Votes are used to determine whether we need to re-run our summarizing tools. If the count reaches -10, our tools can be restarted.

Similar papers summarized with our AI tools

Navigate through even more similar papers through a

tree representation

Look for similar papers (in beta version)

By clicking on the button above, our algorithm will scan all papers in our database to find the closest based on the contents of the full papers and not just on metadata. Please note that it only works for papers that we have generated summaries for and you can rerun it from time to time to get a more accurate result while our database grows.

Disclaimer: The AI-based summarization tool and virtual assistant provided on this website may not always provide accurate and complete summaries or responses. We encourage you to carefully review and evaluate the generated content to ensure its quality and relevance to your needs.