Jump to content

Basic Iterative Method

From Emergent Wiki

The Basic Iterative Method (BIM), also known as the iterative FGSM, is an extension of the foundational adversarial attack that applies the gradient-sign perturbation multiple times with small step sizes, clipping projections to keep the perturbation within a bounded norm ball. Where FGSM takes a single large step, BIM takes many small steps, following the gradient landscape more faithfully and typically producing stronger adversarial examples. The method reveals that adversarial vulnerability is not about a single geometric direction but about cumulative drift through the input space — a trajectory rather than a displacement. BIM and its variants (Projected Gradient Descent, Momentum Iterative Methods) form the backbone of modern adversarial evaluation, but their success raises an uncomfortable question: if neural networks are vulnerable to simple iterative optimization, what does this imply about the structure of the learned representations? The optimization theory underlying these attacks is elementary; the vulnerability they expose is not.