Adversarial ML
Adversarial ML adversarial ml · attacks & defenses updated 2026-08-18
// archive

Every classifier has a blind spot.

Adversarial ML coverage for engineers shipping ML systems. Evasion, data poisoning and backdoors, model extraction, membership inference, training-data extraction, and the multimodal attacks that ride a shared vision encoder into every model downstream of it. Built from the published papers and reference implementations, with the threat model each result assumes stated up front.

Enter the archive →

Latest entries

// index10 of 26 entries

Adversarial Attack Libraries: ART, Foolbox, torchattacks

tooling

CLIP Adversarial Attacks: One Perturbation, Every Model

attacks

GraphRP: A Structure-Aware Defense Against GNN Model Extraction

defenses

Best AI Red Teaming Tools for ML Models in 2026

tooling

Data Poisoning Attack Detection Methods That Actually Work

defenses

Adversarial Training Best Practices That Survive Evaluation

defenses

PLAA: A 92.78% NIDS Evasion Rate and Feature-Space Attacks

attacks

Embedding Inversion: Reconstructing Text From Vectors

privacy

Testing Robustness Against Unforeseen Adversaries: The UAR Metric

evaluation

Adversarial Training Methods: PGD-AT, TRADES, and MART

defenses

Start here: one entry per attack family

The archive runs newest first. This is the other way in — the reference piece for each family, from the perturbation that fools one classifier to the one perturbation that steers every model built on a shared encoder.

Not sure which apply to your model? Filter the attack catalogue by access level, modality, adversary goal and the defenses already in place.

Independent, specialist, and free to read

Adversarial ML publishes focused, sourced guides on a single topic. No paywall, no account, no ad tracking.

Subscribe

Adversarial ML — in your inbox

Working adversarial ML — exploits, defenses, and the gap between — delivered when there's something worth your inbox.

No spam. Unsubscribe anytime.