paper-with-me

Papers

Are adversarial examples inevitable?

2018-09-06 · ICLR 2019 5 · Ali Shafahi, W. Ronny Huang, Christoph Studer, Soheil Feizi, Tom Goldstein

A wide range of defenses have been proposed to harden neural networks against adversarial attacks. However, a pattern has emerged in which the majority of adversarial defenses are quickly broken by new attacks. Given the lack of success at generating robust defenses, we are led to ask a fundamental question: Are adversarial attacks inevitable? This paper analyzes adversarial examples from a theoretical perspective, and identifies fundamental bounds on the susceptibility of a classifier to adversarial attacks. We show that, for certain classes of problems, adversarial examples are inescapable. Using experiments, we explore the implications of theoretical guarantees for real-world problems and discuss how factors such as dimensionality and image complexity limit a classifier's robustness against adversarial examples.

📄 PDF Abstract BibTeX arXiv:1809.02104

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

A Bayes-Optimal View on Adversarial Examples

2020-02-20 · Eitan Richardson, Yair Weiss

Since the discovery of adversarial examples - the ability to fool modern CNN classifiers with tiny perturbations of the input, there has been much discussion whether they are a "bug" that is specific to current neural ar…

Adversarial Attack

AdvFAS: A robust face anti-spoofing framework against adversarial examples

2023-08-04 · Jiawei Chen, Xiao Yang, Heng Yin, Mingzhi Ma 외

Ensuring the reliability of face recognition systems against presentation attacks necessitates the deployment of face anti-spoofing techniques. Despite considerable advancements in this domain, the ability of even the mo…

Adversarial DefenseFace Anti-SpoofingFace Recognition

Recent Advances in Understanding Adversarial Robustness of Deep Neural Networks

2020-11-03 · Tao Bai, Jinqi Luo, Jun Zhao

Adversarial examples are inevitable on the road of pervasive applications of deep neural networks (DNN). Imperceptible perturbations applied on natural samples can lead DNN-based classifiers to output wrong prediction wi…

Adversarial Robustness

Subspace Defense: Discarding Adversarial Perturbations by Learning a Subspace for Clean Signals

2024-03-24 · Rui Zheng, Yuhao Zhou, Zhiheng Xi, Tao Gui 외

Deep neural networks (DNNs) are notoriously vulnerable to adversarial attacks that place carefully crafted perturbations on normal examples to fool DNNs. To better understand such attacks, a characterization of the featu…

Adversarial Defense

Dompteur: Taming Audio Adversarial Examples

2021-02-10 · Thorsten Eisenhofer, Lea Schönherr, Joel Frank, Lars Speckemeier 외

Adversarial examples seem to be inevitable. These specifically crafted inputs allow attackers to arbitrarily manipulate machine learning systems. Even worse, they often seem harmless to human observers. In our digital so…

Automatic Speech RecognitionAutomatic Speech Recognition (ASR)speech-recognitionSpeech Recognition