כתבה
arXiv cs.LG ·
Fast Adversarial Attacks with Gradient Prediction
תקציר מקורי באנגליתarXiv:2605.14868v2 Announce Type: replace Abstract: Generating adversarial examples at scale is a core primitive for robustness evaluation, adversarial training, and red-teaming, yet even "fast" attacks such as FGSM remain throughput-limited by the cost of a backward pass. We introduce a family of attacks that eliminates the backward pass by predicting the input gradient from forward-pass hidden states via a lightweight linear regression. Theoretically, we derive exact affine conditional gradient means, showing optimality in the (idealized) NTK regime. Empirically, our methods work when applied to practical finite-width models; we recover much of FGSM's attack performance while using only a small fraction of the time, corresponding to a $532\%$ increase in throughput. These results suggest
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית