New Framework Evaluates AI Robustness with Minimum-Norm Attacks

Luca Scionis, Luca Melis, Maura Pintor, Fabio Brau, Ambra Demontis, Giorgio Fumera, Fabio Roli, Battista Biggio· July 23, 2026 View original

Summary

Researchers introduce a unified framework for evaluating adversarial robustness using a comprehensive pool of minimum-norm attacks and robustness-perturbation curves across multiple norms. This approach addresses limitations of fixed-epsilon evaluations, providing a more stable and controllable assessment of AI model defenses.

Current methods for evaluating adversarial robustness typically rely on predefined attack ensembles, like AutoAttack, at a single perturbation budget (epsilon) and a limited selection of perturbation norms. This approach has significant limitations, as robustness-perturbation curves can intersect, making single-epsilon rankings unstable and providing no guarantee of worst-case performance. This paper proposes a new, unified evaluation framework centered on a comprehensive pool of minimum-norm attacks and the generation of robustness-perturbation curves across L0, L1, L2, and L-infinity norms. The "attack frontier" is defined as the worst-case robustness estimate derived from this attack pool. The framework formalizes evaluation as an "attack frontier approximation problem," constructing optimized subsets of attacks that approach the frontier under a controllable query budget. It also introduces the "defense frontier" and a "Defense Optimality Index" to rank defenses without needing a reference epsilon. On CIFAR-10 and ImageNet, these ensembles consistently match or exceed AutoAttack's performance at various budget tiers, offering a more robust and flexible evaluation alternative.

Why it matters

Professionals developing and deploying AI systems, especially in security-sensitive domains, can use this framework to gain a more comprehensive, stable, and cost-controlled understanding of their models' adversarial robustness.

How to implement this in your domain

  1. 1Adopt the proposed minimum-norm attack ensembles and robustness-perturbation curves for a more thorough evaluation of AI model security.
  2. 2Implement the "Defense Optimality Index" to objectively rank and compare different adversarial defenses without relying on arbitrary epsilon values.
  3. 3Integrate query-controlled attack budgets into robustness testing pipelines to manage evaluation costs effectively.
  4. 4Educate security and AI engineering teams on the limitations of single-epsilon robustness evaluations and the benefits of curve-based assessments.

Who benefits

CybersecurityAutomotiveDefenseHealthcareFinance

Key takeaways

  • Fixed-epsilon adversarial robustness evaluations are fundamentally limited and unstable.
  • A new framework uses minimum-norm attack ensembles and robustness-perturbation curves for comprehensive evaluation.
  • The "attack frontier" and "defense frontier" provide more stable and objective robustness metrics.
  • This method offers query-controlled, curve-based evaluation, outperforming AutoAttack at various budgets.

Original post by Luca Scionis, Luca Melis, Maura Pintor, Fabio Brau, Ambra Demontis, Giorgio Fumera, Fabio Roli, Battista Biggio

"arXiv:2607.19855v1 Announce Type: new Abstract: Adversarial robustness is commonly evaluated with predefined attack ensembles, such as AutoAttack, at a single perturbation budget $\varepsilon$ and on a selective choice of perturbation norms. We argue this formulation is fundament…"

View on X

Originally posted by Luca Scionis, Luca Melis, Maura Pintor, Fabio Brau, Ambra Demontis, Giorgio Fumera, Fabio Roli, Battista Biggio on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses