[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-study-says-default-settings-for-ai-attacks-are-wrong":10,"sections":34},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":29,"feedback":33,"feedback_at":22,"cost_usd":33,"total_tokens":33},6963,"study-says-default-settings-for-ai-attacks-are-wrong","Study Says Default Settings for AI Attacks Are Wrong","New research finds that the standard math used to test how easily AI image models can be fooled is often tuned to the wrong setting.","Turns out the industry's go-to formula for attacking AI image models has been picking a suboptimal setting most of the time.\n\nResearchers studied adversarial attacks, the deliberately corrupted images used to test whether AI models can be tricked into misclassifying what they see. These attacks are built under mathematical constraints called Lp norms, and almost everyone defaults to p=1 or p=2. The team introduced new ways to measure how sparse (few pixels changed) and smooth (visually subtle) an attack is, then tested attacks across multiple image datasets and both convolutional and transformer-based models. Across most tasks, p=1 and p=2 turned out to be the wrong call. Values between 1.3 and 1.5 produced attacks that were both more sparse and more smooth than the standard settings.\n\nThis matters because Lp norms are not just an academic detail. They are the baseline researchers and security teams use to benchmark how robust a model is against manipulation. If the field has been testing models against attacks tuned to a suboptimal p value, robustness claims built on those tests may understate real vulnerabilities that show up at p=1.3 to 1.5.\n\nNobody is claiming a new attack technique here, just a better dial setting on an old one. But given how much AI safety research leans on these benchmarks, a mistuned dial is not a small detail.","[\"adversarial attacks\",\"ai security\",\"machine learning research\"]","2026-09-18T04:00:00.000Z","2026-09-19T00:43:40.146Z","2026-09-19T00:43:52.060Z","published",null,[],"ai",[26,27,28],"adversarial attacks","ai security","machine learning research",[30],{"name":31,"url":32},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2602.06578",0,{"sections":35},[36,39,43,48,53,57,61,66,70,75,80,85,90,95],{"name":37,"slug":24,"count":38,"latest_published_at":18},"AI",4082,{"name":40,"slug":41,"count":42,"latest_published_at":18},"Security","security",661,{"name":44,"slug":45,"count":46,"latest_published_at":47},"Policy","policy",339,"2026-09-17T12:00:00.000Z",{"name":49,"slug":50,"count":51,"latest_published_at":52},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":54,"slug":55,"count":56,"latest_published_at":18},"Hardware","hardware",155,{"name":58,"slug":59,"count":60,"latest_published_at":18},"Science","science",125,{"name":62,"slug":63,"count":64,"latest_published_at":65},"Consumer Tech","consumer-tech",99,"2026-09-09T17:27:33.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":18},"Dev Tools","dev-tools",78,{"name":71,"slug":72,"count":73,"latest_published_at":74},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Startups","startups",55,"2026-09-09T23:14:29.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"General","general",41,"2026-09-08T01:57:23.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]