arXiv:2510.16440cs.LGcs.CR2025-10

针对高能物理分类模型,设计高效小扰动攻击方法并夺冠。

Colliding with Adversaries at ECML-PKDD 2025 Adversarial Attack Competition 1st Prize Solution

  • 多轮梯度优化结合随机初始化与样本混合提升攻击效果。
  • 在最小扰动下实现最高误分类率,击败其他参赛方案。
  • 适合研究对抗攻击、模型鲁棒性或高能物理安全性的学者。

本文介绍在ECML-PKDD 2025高能物理发现中的鲁棒学习挑战赛任务1的冠军解决方案。该任务要求设计一种对抗攻击,以最大化分类错误的同时最小化输入扰动。我们的方法采用多轮基于梯度的策略,利用模型的可微结构,并引入随机初始化和样本混合技术以增强攻击有效性。所提出的攻击在扰动幅度和欺骗成功率两方面均表现最优,最终获得竞赛第一名。

原文摘要 · Abstract (English)

This report presents the winning solution for Task 1 of Colliding with Adversaries: A Challenge on Robust Learning in High Energy Physics Discovery at ECML-PKDD 2025. The task required designing an adversarial attack against a provided classification model that maximizes misclassification while minimizing perturbations. Our approach employs a multi-round gradient-based strategy that leverages the differentiable structure of the model, augmented with random initialization and sample-mixing techniques to enhance effectiveness. The resulting attack achieved the best results in perturbation size and fooling success rate, securing first place in the competition.

对抗攻击高能物理模型鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。