A benchmarking framework and its validation on all evasion attacks on image classifiers listed in the adversarial robustness toolbox

What is an efficient attack against image classifiers? First, this paper defines a generic benchmarking framework to evaluate the effectiveness of evasion attacks against image classification models with relevant key performance indicators. The framework assesses attacks on 12 classifiers, for 4 datasets, and all supported attack typologies and scenarios, and specifies the tools to compare different attacks. Second, the framework is experimentally validated. We benchmark each of the 27 evasion attacks implemented in the Adversarial Robustness Toolbox, what leads to useful observations. With experiments that encompass 669,034 attack attempts and represent ∼ 7.6 GPU years of sequential computing time, our survey is the most comprehensive evaluation of evasion attacks to date. This work enables the intrinsic evaluation and comparative positioning of any new evasion attack.

Authors

Institutions

Publication Details

Journal
Journal of Information and Telecommunication
Published
2026-09-29
DOI
https://doi.org/10.1080/24751839.2026.2730085
Primary Topic
Adversarial Robustness in Machine Learning
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

A benchmarking framework and its validation on all evasion attacks on image classifiers listed in the adversarial robustness toolbox

Enea Mançellari, Franck Leprévost, Ali Osman Topal, Elmir Avdusinovic et al.
Journal of Information and Telecommunication
Adversarial Robustness in Machine Learning
article

A benchmarking framework and its validation on all evasion attacks on image classifiers listed in the adversarial robustness toolbox

Enea Mançellari, Franck Leprévost, Ali Osman Topal, Elmir Avdusinovic, Volker Müller
article en

Abstract

What is an efficient attack against image classifiers? First, this paper defines a generic benchmarking framework to evaluate the effectiveness of evasion attacks against image classification models with relevant key performance indicators. The framework assesses attacks on 12 classifiers, for 4 datasets, and all supported attack typologies and scenarios, and specifies the tools to compare different attacks. Second, the framework is experimentally validated. We benchmark each of the 27 evasion attacks implemented in the Adversarial Robustness Toolbox, what leads to useful observations. With experiments that encompass 669,034 attack attempts and represent ∼ 7.6 GPU years of sequential computing time, our survey is the most comprehensive evaluation of evasion attacks to date. This work enables the intrinsic evaluation and comparative positioning of any new evasion attack.

Journal of Information and Telecommunication
University of Luxembourg (LU)
Openalex Percentile: Top 10%
Adversarial Robustness in Machine Learning
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.