Good Papers

Don't Waste the Noise: Importance-Guided Perturbation Allocation under Joint Global and Local Constraints

Importance-guided allocation directs limited $\ell_1$ perturbation budgets toward model-sensitive regions via fixed clean-gradient priors, boosting attack success by 2.52, 17.70 points across ten robust configurations without increasing global consumption.

Melika Shirian, Kianoosh Vadaei

Published Oct 1, 2026arXiv ↗

80%
OverallMust read
?
OverallMust readVote to see the scoreThe exact score shows once you've voted, so every vote is your own call. The first half of each home page shelf shows its scores.
Readers
–

Only vote on papers you've read. Sign in with GitHub to vote.

AI panel12/20reviewers recommend it
lenient 4/5
medium 6/10
strict 2/5
AI panel?Vote to see what the 20 AI reviewers said
Panel consensus
A sharp importance-guided redistribution of fixed perturbation budgets yields substantial attack gains under joint global and local constraints, though its fixed-gradient allocation mechanism risks being seen as an overbranded budget tweak rather than a lasting framework.

Abstract

Adversarial optimization under a shared $\ell_1$ budget requires deciding not only how much perturbation to use, but also where that limited budget should be spent. This allocation problem becomes particularly important when individual input coordinates are subject to local magnitude constraints, which restrict the extent to which perturbation can be concentrated on a small number of locations. We introduce an importance-guided allocation mechanism that uses a fixed clean-gradient prior to steer perturbation toward model-sensitive regions while leaving the feasible perturbation set unchanged. A centered allocation objective encourages perturbation at above-average importance locations and discourages unnecessary expenditure elsewhere, thereby redistributing rather than enlarging the available budget. Across ten robust model--dataset configurations under a common capacity-limited threat setting, the proposed method improves attack success over matched APGD- and PMA-based baselines by $2.52$ to $17.70$ percentage points. Allocation analysis shows that these gains are accompanied by substantially greater perturbation mass in high-importance regions without increased global $\ell_1$ consumption. Mechanism ablations further show that centered non-uniform redistribution provides part of the benefit, while model-derived importance yields an additional improvement. These results identify perturbation allocation as a distinct and practically relevant dimension of adversarial optimization under shared-budget, locally constrained threat models.