Motivating the Rules of the Game for Adversarial Example Research

In this paper, the authors argue that adversarial example defense papers have, to date, mostly considered abstract, toy games that do not relate to any specific security concern. Furthermore, defense papers have not yet precisely described all the abilities and limitations of attackers that would be relevant in practical security. Towards this end, they establish a taxonomy of motivations, constraints, and abilities for more plausible adversaries.


