Home▸AI & Machine Learning▸AI Security: Adversarial Attacks on a Classifier Decision Boundary (2D)

AI Security: Adversarial Attacks on a Classifier Decision Boundary (2D)

2D companion: watch a classifier's decision boundary in a plain scatter plot, then push points across it with a bounded adversarial perturbation. Tune the attack budget, attack steps and adversarial-training defense, and read clean vs robust accuracy live alongside a full accuracy-vs-ε curve.

AI & Machine Learning2DAdvanced60 FPS📱 Mobile-adapted⇄ 3D version
2d-ai-security-adversarial-attacks-on-a-classifier-decision ↗ Open standalone

This 2D companion drives the exact same attack math as the 3D version — bounded FGSM/PGD-style perturbations pushing points across a linear decision boundary, with an adversarial-training defense that widens the margin — through a flat scatter plot plus a live accuracy-vs-ε curve, so the tradeoff between attack strength and defense is readable as two numbers and a line instead of an orbiting scene.

⚙ Under the hood

2D adversarial-attack lab: bounded FGSM/PGD-style perturbation pushes points across a linear decision boundary, an adversarial-training toggle widens the margin, and a live accuracy-vs-ε curve shows the whole attack-strength tradeoff at once.

AIAI SecurityAdversarial AttacksRobustnessDecision Boundary

2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install

What is an adversarial attack on a classifier?

A bounded perturbation added to an input — here, a point in embedding space — chosen to push it across a model's decision boundary while staying within a small budget ε, so the change is imperceptible but the model's output flips.

What's the difference between FGSM and PGD?

FGSM is a single-step attack: it takes one jump of size ε in the direction that most increases the model's loss. PGD repeats that step several times with a smaller step size and clips back into the ε-ball each time, making it a stronger attack for the same budget.

Does adversarial training actually help?

Yes — retraining on adversarial examples widens the model's effective decision margin, so the same perturbation budget ε flips fewer points. It doesn't eliminate the attack surface, but it shrinks it, which is why the robust-accuracy curve sits higher when the defense is on.

What did you find?

Add reproduction steps (optional)