Presentation
Late Breaking Results: ROAST: Reverse-Training Offset Attack on Spatial Sampling Topologies
DescriptionLocal Binary Pattern Network (LBPNet) concentrates representational power in a small set of learned spatial sampling offsets, creating a high-leverage fault surface. We propose ROAST, a white-box reverse-training attack that updates only offsets to maximize the loss, then maps adversarial offsets to a minimal-bit-flip schedule using truncated Hamming distance on FP32 encodings. On MNIST and SVHN, ROAST induces >70% and 64% accuracy drops while flipping only ~4–5% of offset bits, outperforming BFA in damage-per-bit and avoiding border-saturation artifacts.
Event Type
Late Breaking Results
TimeMonday, July 276:14pm - 6:17pm PDT
LocationExhibit Hall
