acceptodds
Under review as a conference paper at ICLR 2027

A Mirror Descent Framework for Adversarial Attacks over the Clipped Ball and Group Sparsity Constraints

Abstract

We introduce a Mirror Descent framework to solve optimization problems over a clipped ball, generalizing the -APGD algorithm to group-norm constraints. We resolve the expensive high-dimensional Bregman projection by reducing it to a continuous resource-allocation problem that is computed exactly via a efficient 1D root search. Furthermore, we propose a structurally relaxed projection that decouples within-group coordinate dependencies, reducing computational overhead while systematically enforcing group sparsity. Instantiating this framework as Group-Structured Mirror Descent (GSMD) for adversarial attack, our extensive evaluations on ImageNet reveal a clear trade-off: the exact projection accelerates objective convergence, whereas the relaxation yields strictly sparser modifications. GSMD generates localized, coherent perturbations and achieves state-of-the-art attack success rates on both standard and robust classifiers, requiring significantly fewer backward passes than existing structured attacks.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.