Every classifier has a blind spot.
Adversarial ML coverage for engineers shipping ML systems. Evasion, data poisoning and backdoors, model extraction, membership inference, training-data extraction, and the multimodal attacks that ride a shared vision encoder into every model downstream of it. Built from the published papers and reference implementations, with the threat model each result assumes stated up front.
Enter the archive →Latest entries
Adversarial Attack Libraries: ART, Foolbox, torchattacks
toolingCLIP Adversarial Attacks: One Perturbation, Every Model
attacksGraphRP: A Structure-Aware Defense Against GNN Model Extraction
defensesBest AI Red Teaming Tools for ML Models in 2026
toolingData Poisoning Attack Detection Methods That Actually Work
defensesAdversarial Training Best Practices That Survive Evaluation
defensesPLAA: A 92.78% NIDS Evasion Rate and Feature-Space Attacks
attacksEmbedding Inversion: Reconstructing Text From Vectors
privacyTesting Robustness Against Unforeseen Adversaries: The UAR Metric
evaluationAdversarial Training Methods: PGD-AT, TRADES, and MART
defensesStart here: one entry per attack family
The archive runs newest first. This is the other way in — the reference piece for each family, from the perturbation that fools one classifier to the one perturbation that steers every model built on a shared encoder.
- Evasion Evasion Attacks on Image Classifiers: FGSM, PGD, and C&W
- Multimodal Adversarial Attacks on Vision-Language Models: CLIP, LLaVA, GPT-4
- CLIP CLIP Adversarial Attacks: One Perturbation, Every Model
- Poisoning Data Poisoning and Backdoor Attacks on Foundation Models
- Privacy Membership Inference Attacks: What Works on Production ML APIs
- Extraction Model Extraction via Query-Based Functional Stealing
- Evaluation Evaluating Adversarial Robustness Without Fooling Yourself
- Tooling Adversarial Attack Libraries: ART, Foolbox, torchattacks
Not sure which apply to your model? Filter the attack catalogue by access level, modality, adversary goal and the defenses already in place.
Independent, specialist, and free to read
Adversarial ML publishes focused, sourced guides on a single topic. No paywall, no account, no ad tracking.
Adversarial ML — in your inbox
Working adversarial ML — exploits, defenses, and the gap between — delivered when there's something worth your inbox.
No spam. Unsubscribe anytime.