Skip to content
Preprint

Adversarial Training of Linear Models under Stealthy Attacks

Aug 2026 · 0 citations · 12 references
Computer Science Engineering

TL;DR

A detector-based switched model is proposed, in which optimal attack strategies are stealthy, and a convex formulation of the resulting adversarial risk is derived for linear prediction models.

Abstract

Predictive models are widely used in many fields, but are vulnerable to false data injection attacks. To address this, detection schemes and adversarial training have been proposed, but such approaches lack guarantees against stealthy attacks. We therefore propose a detector-based switched model, in which optimal attack strategies are stealthy. For linear prediction models, we derive a convex formulation of the resulting adversarial risk. The model incorporates protected features and introduces a hyperparameter modelling attack probability, enabling an explicit performance trade-off between clean and attacked data regimes. Numerical simulations on real and synthetic data show improved performance on partially attacked data, even for misspecified attack probabilities.

View source

Similar papers

2026

Rethinking Fake Adversarial Examples for Single-Step Adversarial Training

Adversarial training (AT) is a widely adopted defense against adversarial attacks, but its multi-step optimization process for generating adversarial examples leads to substantial computational overhead. To mitigate this, various single-step adversarial training methods have been proposed. However, these models often s...

Lifeng Huang, Yuquan Lin, Chen Wan et al. · 0 citations
Open access 2026

Adversarial Training Foundations: Methods to Enhance Neural Network Robustness

The study systematically compares two distinct adversarial training strategies: ‘pre-train’, where adversarial examples are generated beforehand, and ‘in-train’, where perturbations are introduced dynamically during the training process, to understand the advantages and limitations of each approach in enhancing model r...

José María Jorquera Valero, Ibon Bengoechea Cazorla, Manuel Gil Pérez · 0 citations
Jul 2026

Random Logit Scaling: Defending Deep Neural Networks Against Black-Box Score-Based Adversarial Example Attacks

Machine learning models are increasingly adapted in various domains. However, adversarial examples pose a significant threat to the reliable deployment of these models. In recent years, some powerful adversarial example attacks have been proposed for the fast and query-efficient generation of adversarial examples, even...

Hamid Dashtbani, Mehdi Dousti Gandomani, A. M. Sadeghzadeh · 0 citations
Conference Jul 2026

Rethinking the Transferable Adversarial Attacks and Robust Defense in Federated Learning

To mitigate the attacks of transferable adversarial examples, a defense mechanism stemming from the transferability of model robustness by adversarial training is designed, gaining insights into adversarial examples and the vulnerability of federated learning systems.

Zuobin Xiong, Deval Mukherjee, Homook Cho et al. · 0 citations
#artificial intelligence Preprint Sep 2026

What Makes Adversarial Examples Transfer Across Deepfake Detectors?

Deepfake detectors remain vulnerable to transfer-based black-box attacks, in which adversarial examples are generated on a source surrogate model and transferred to a target model, unknown to the attacker. Yet how source--target compatibility shapes attack success remains poorly understood. Prior studies evaluate limit...

Rafael M. Mamede, Pedro C. Neto, A. F. Sequeira · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.