Explaining and Harnessing Adversarial Examples
Explore this paper's citation graph
Summary
It is argued that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature, supported by new quantitative results while giving the first explanation of the most intriguing fact about them: their generalization across architectures and training sets.
- Type
- preprint
- Published
- 2014-12-19
- Cited by
- 23,012
- References
- 19
- Access
- Open access
- OpenAlex
- https://openalex.org/W1945616565
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:6706414
Keywords
Adversarial system, Overfitting, MNIST database, Computer science, Machine learning
References
- Theano: new features and speed improvements
- Intriguing properties of neural networks
- Pylearn2: a machine learning research library
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
- Long Short-Term Memory
- Dropout: a simple way to prevent neural networks from overfitting
- Going deeper with convolutions
- Multi-Prediction Deep Boltzmann Machines
- ImageNet: A large-scale hierarchical image database
- Multilayer feedforward networks are universal approximators
- Deep Sparse Rectifier Neural Networks
- Large Scale Distributed Deep Networks
- Spatiotemporal elements of macaque v1 receptive fields.
- Maxout Networks
- What is the best multi-stage architecture for object recognition?
- Learning Multiple Layers of Features from Tiny Images
- Visual Causal Feature Learning
- Multilayer feedforward networks are universal approximators
- Maxout Networks
Cited by
- Enhance Visual Recognition Under Adverse Conditions via Deep Networks
- Convolutional Channel Features
- How Well Can a CNN Marginalize Simple Nuisances It is Designed for?
- LSUN: Construction of a Large-scale Image Dataset using Deep Learning with Humans in the Loop
- Dropout as data augmentation
- Invariant backpropagation: how to train a transformation-invariant neural network
- Analysis of classifiers’ robustness to adversarial perturbations
- Lateral Connections in Denoising Autoencoders Support Supervised Learning
- Class Probability Estimation via Differential Geometric Regularization
- On Pixel-Wise Explanations for Non-Linear Classifier Decisions by Layer-Wise Relevance Propagation
- Characterization of the equivalence of robustification and regularization in linear and matrix regression
- Understanding Neural Networks Through Deep Visualization
- Qualitatively characterizing neural network optimization problems
- Maximum-Margin Structured Learning with Deep Networks for 3D Human Pose Estimation
- Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
- Deep Learning and Music Adversaries
- Qualitative Robustness in Bayesian Inference
- Filter-Invariant Image Classification on Social Media Photos
- Visual Language Modeling on CNN Image Representations
- Confusing Deep Convolution Networks by Relabelling
Related papers
- Learning Multiple Layers of Features from Tiny Images
- Deep Learning
- Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples
- Practical Black-Box Attacks against Machine Learning
- Universal Adversarial Perturbations
- Adversarial examples in the physical world
- DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks