Shared Vulnerabilities in Robustness-Optimized Defenses: One Breach Exposes the Family
A new preprint identifies a systemic security risk in adversarial robustness-optimized machine learning defenses: breaching one defense can expose vulnerabilities across an entire family of related defenses. The authors introduce stricter transfer-only attack protocols and a simple adaptive attack, PGDTransfer, which achieves an average 80.4% transfer attack success rate against purification-based defenses. They also propose Adversarial Sensitivity Maps to visualize shared vulnerabilities and argue that future defenses should prioritize vulnerability diversity and transfer-only isolation.
Why it matters: This work reveals that many current adversarial defenses may share exploitable weaknesses, challenging the reliability of robustness-optimized models and suggesting a need for new security objectives.
Full story at: arXiv Cryptography and Security ↗