A field guide to AI positions

Adversarial examples

Publication dates and source age

Sources counted: 2

Newest dated source: 2025-03-24

At least one source was published within the 18-month window.

Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

Open in the glossary Reading notes · Structured record

In plain language

Inputs deliberately changed to make a model give a wrong result; testing them can reveal weaknesses. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Limits & distinctions

These attacks act on inputs during use. Data poisoning instead alters material used for training. A defense evaluated against one attack need not stop another. [2]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

A fuller explanation

In a classic image example, small carefully chosen changes cause a classifier to give the wrong label. The term covers crafted inputs, not simply every difficult or unfamiliar example. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

How it relates to the map

Atlas reading question: does a security claim cover deliberate manipulation, and under what conditions? [2]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Share this page

https://theaiatlas.org/ideas/adversarial-examples/

Download a share image · Vector image

Image previews are summaries. Keep the page link so readers can check the evidence.

Sources and what we read

  1. 1. Explaining and Harnessing Adversarial Examples

    Source is over 18 months old.

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2014-12-20

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read the abstract and version history. Supports deliberately modified inputs that cause misclassification and adversarial training as a proposed response. Findings are scoped to the studied models and attacks.

  2. 2. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2025-03-24

    At least one source was published within the 18-month window.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read the executive summary, attack-stage definitions, and sections 3.2.1 to 3.2.3 on generative-model poisoning and mitigations. Publication date comes from the NIST publication record. No claim is made that one defense stops all attacks.

Edition and machine-readable evidence

Content version 0.20.0. Evidence cutoff 2026-09-15; this does not mean every source was read on that day.

Pinned complete dataset · Complete evidence page · Agent consumption guide