When Competitor Rankings Mislead: Dynamic Competitor Discovery for Untargeted Adversarial Attacks
Abstract
Untargeted adversarial attacks need only cross the decision boundary of a single competing class, yet determining which competitor to pursue remains challenging. Class logits provide readily available guidance, but their rankings can change during optimization. Early target commitment or score-dependent gradient weighting can therefore place excessive emphasis on transient rankings and steer optimization toward less promising competitors. We introduce Dynamic Competitor Discovery (DCD), which treats target selection as a coarse-to-fine process under uncertain competitor rankings. DCD begins with a broad candidate set, progressively narrows it as optimization proceeds, and selects a single target only after sufficient evidence has accumulated. DCD- extends this process to multiple targets by repeating DCD while excluding previously selected competitors. Across ten benchmark models and four datasets, DCD with PGD, APGD, GAMA, FAB, and FMN improves the corresponding base attacks in 49 of 50 attack–model comparisons under equal or lower gradient budgets, with consistent gains also observed under . Applied after AutoAttack, APGD-DCD9 uncovers 88 additional adversarial examples across all ten models, revealing vulnerabilities missed by AutoAttack.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.