How do I decide which norm to use for placing a constraint on my adversarial perturbation?


I am performing an adversarial machine learning attack on a neural network for network traffic classification. For adding adversarial perturbations in features such as packet interarrival times and packet size, what norm should I use as a constraint? (eg. l1 norm, l2 norm, l-infinity norm, etc.)


1You should provide some details about where are you applying exactly the norm to. You're saying you're using it for placing a constraint, but it's not clear, unless someone knows what you're talking about. – nbro – 2020-03-31T11:04:06.577

