A benchmarking framework and its validation on all evasion attacks on image classifiers listed in the adversarial robustness toolbox
What is an efficient attack against image classifiers? First, this paper defines a generic benchmarking framework to evaluate the effectiveness of evasion attacks against image classification models with relevant key performance indicators. The framework assesses attacks on 12 classifiers, for 4 datasets, and all supported attack typologies and scenarios, and specifies the tools to compare different attacks. Second, the framework is experimentally validated. We benchmark each of the 27 evasion attacks implemented in the Adversarial Robustness Toolbox, what leads to useful observations. With experiments that encompass 669,034 attack attempts and represent ∼ 7.6 GPU years of sequential computing time, our survey is the most comprehensive evaluation of evasion attacks to date. This work enables the intrinsic evaluation and comparative positioning of any new evasion attack.
Authors
- Enea Mançellari (ORCID: https://orcid.org/0000-0002-8562-1433)
- Franck Leprévost (ORCID: https://orcid.org/0000-0001-8808-2730)
- Ali Osman Topal (ORCID: https://orcid.org/0000-0003-0141-4742)
- Elmir Avdusinovic (ORCID: https://orcid.org/0000-0002-8292-8747)
- Volker Müller (ORCID: https://orcid.org/0000-0001-7335-7682)
Institutions
- University of Luxembourg (LU)
Publication Details
- Journal
- Journal of Information and Telecommunication
- Published
- 2026-09-29
- DOI
- https://doi.org/10.1080/24751839.2026.2730085
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00