Securing deep models against adversarial attacks is not primarily a technical puzzle, it is a mathematical one. The researcher who posted this question understands something many in the field overlook: before we can defend models, we must first understand the geometry of the space in which attacks operate. This is a refreshingly clear starting point for a PhD.
The open challenges in adversarial machine learning are not about finding better defenses in isolation. The real problem is that most defenses are reactive. They patch against known attack patterns without addressing the underlying structure that makes models vulnerable. This is where differential geometry and dynamical systems become more than academic curiosities. An adversarial perturbation is, at its core, a small, directed movement through the model's input space. Understanding that space, its curvature, its boundaries, its stable and unstable manifolds, gives you a language to describe why certain inputs are fragile and others are not. The open challenge is to move from describing attacks as statistical anomalies to modeling them as trajectories along a manifold. That shift would allow defenses to anticipate, not just react.
Recent work has begun to explore these connections, though it remains sparse. Researchers have applied concepts from differential geometry to characterize decision boundaries and measure local robustness. Dynamical systems theory has been used to model the iterative nature of gradient-based attacks, treating them as flows that converge to adversarial examples. But the field has not yet built a unified framework. That is the opportunity. A PhD grounded in these mathematical tools could produce something the community lacks: a principled way to reason about adversarial robustness as a property of the model's intrinsic geometry, not as a list of patches. For someone with a math background, this is not a stretch, it is a natural next step.
For practical resources, start with the foundational papers on adversarial examples by Szegedy et al. and Goodfellow et al., then move to the work on certified defenses and Lipschitz continuity. For the mathematical angle, look at papers connecting adversarial robustness to the curvature of decision boundaries, and at any recent work using optimal transport or manifold learning. Do not limit yourself to machine learning venues; differential geometry and dynamical systems papers from applied mathematics conferences will give you the tools to frame your questions. The concrete point is this: the field is waiting for someone to build a bridge. Your background is the blueprint. Start building.