Synthesizing Robust Adversarial Examples
Explore this paper's citation graph
Summary
The existence of robust 3D adversarial objects is demonstrated, and the first algorithm for synthesizing examples that are adversarial over a chosen distribution of transformations is presented, which synthesizes two-dimensional adversarial images that are robust to noise, distortion, and affine transformation.
- Type
- article
- Published
- 2017-07-24
- Cited by
- 1,892
- References
- 34
- OpenAlex
- https://openalex.org/W2963557656
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:2645819
Keywords
Adversarial system, Affine transformation, Computer science, Artificial intelligence, Distortion (music)
References
- Intriguing properties of neural networks
- XIII—The Development of the CIE 1976 (L* a* b*) Uniform Colour Space and Colour‐difference Formula
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks
- The Limitations of Deep Learning in Adversarial Settings
- Rethinking the Inception Architecture for Computer Vision
- Foveation-based Mechanisms Alleviate Adversarial Examples
- DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks
- Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples
- Adversarial examples in the physical world
- Hidden Voice Commands
- Towards Evaluating the Robustness of Neural Networks
- Defensive Distillation is Not Robust to Adversarial Examples
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition
- Universal Adversarial Perturbations
- Practical Black-Box Attacks against Machine Learning
- MagNet: A Two-Pronged Defense against Adversarial Examples
- Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods
- Towards Deep Learning Models Resistant to Adversarial Attacks
- NO Need to Worry about Adversarial Examples in Object Detection in Autonomous Vehicles
- ZOO: Zeroth Order Optimization Based Black-box Attacks to Deep Neural Networks without Training Substitute Models
Cited by
- Robust Physical-World Attacks on Machine Learning Models
- Can you fool AI with adversarial examples on a visual Turing test?
- Robust Physical-World Attacks on Deep Learning Models
- Standard detectors aren't (currently) fooled by physical adversarial stop signs
- Regularization for Deep Learning: A Taxonomy
- Provable defenses against adversarial examples via the convex outer adversarial polytope
- Improving the Adversarial Robustness and Interpretability of Deep Neural Networks by Regularizing their Input Gradients
- Interpretable R-CNN
- Adversarial Attacks Beyond the Image Space
- On the Robustness of Semantic Segmentation Models to Adversarial Attacks
- DANCin SEQ2SEQ: Fooling Text Classifiers with Adversarial Text Example Generation
- Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning
- A Rotation and a Translation Suffice: Fooling CNNs with Simple Transformations
- Generative Adversarial Perturbations
- Adversarial Examples that Fool Detectors
- The Robust Manifold Defense: Adversarial Training using Generative Models
- Deep Learning: A Critical Appraisal
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- Audio Adversarial Examples: Targeted Attacks on Speech-to-Text
- Rogue Signs: Deceiving Traffic Sign Recognition with Malicious Ads and Logos