A New Angle on L2 Regularization
thomas-tanay.github.io
thomas-tanay.github.io
In a high dimensional, linear space you can add epsilon to lots and lots of dimensions in such a way that you can cross that hyperplane, and not all the regularization of the norm in the world will save you.
Both statements are fairly obvious if you've studied functional analysis and probability.
This is a case where pre-ML computer vision didn't have the same problem. I've always felt that something got lost in the transition.
Biggio et al., "Evasion Attacks Against Machine Learning at Test Time", http://www.ecmlpkdd2013.org/wp-content/uploads/2013/07/527.p...
It looks like this article works through something vaguely similar for $\ell_2$ adversarial examples. It would be interesting to compare the author's approach with explicit adversarial training.