Adversarial Risk in the Generative AI Era Necessitates Dropping the Small Epsilon Ball
Andrew Cullen ⋅ Neil Marchant ⋅ Paul Montague ⋅ Jiani Xie ⋅ Benjamin Rubinstein
Abstract
Adversarial Machine Learning research is currently centered on the search for the $\epsilon$-ball: minimal perturbations designed to fool models while remaining imperceptible to humans. We argue that this fixation on $\ell_p$ norms is a metrological trap that communicates a distorted perception of risk to defenders, one that is unaligned with real-world system vulnerabilities. This paradigm misleads defenders into optimizing for narrow, mathematical robustness at the expense of systemic security, while simultaneously incentivizing attackers to exploit non-overlapping alternative adversarial pathways. Ultimately, we argue that the dominance of the $\ell_p$ ball does not just fail to reduce harm - it may actively facilitate it by communicating a false sense of security against the wrong threats.
Chat is not available.
Successful Page Load