paper-with-me

홈 › Papers

Most Convolutional Networks Suffer from Small Adversarial Perturbations

2026-02-03 · Amit Daniely, Idan Mehalel arxiv

The existence of adversarial examples is relatively understood for random fully connected neural networks, but much less so for convolutional neural networks (CNNs). The recent work [Daniely, 2025] establishes that adversarial examples can be found in CNNs, in some non-optimal distance from the input. We extend over this work and prove that adversarial examples in random CNNs with input dimension $d$ can be found already in $\ell_2$-distance of order $\lVert x \rVert /\sqrt{d}$ from the input $x$, which is essentially the nearest possible. We also show that such adversarial small perturbations can be found using a single step of gradient descent. To derive our results we use Fourier decomposition to efficiently bound the singular values of a random linear convolutional operator, which is the main ingredient of a CNN layer. This bound might be of independent interest.

📄 PDF Abstract BibTeX arXiv:2602.03415

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Biologically Inspired Mechanisms for Adversarial Robustness

2020-06-29 · NeurIPS 2020 12 · Manish V. Reddy, Andrzej Banburski, Nishka Pant, Tomaso Poggio

A convolutional neural network strongly robust to adversarial perturbations at reasonable computational and performance cost has not yet been demonstrated. The primate visual ventral stream seems to be robust to small pe…

Adversarial Robustness

Aliasing coincides with CNNs vulnerability towards adversarial attacks

2021-11-22 · AAAI Workshop AdvML 2022 2 · Julia Grabinski, Janis Keuper, Margret Keuper

Many commonly well-performing convolutional neural network models have shown to be susceptible to input data perturbations, indicating a low model robustness. Adversarial attacks are thereby specifically optimized to rev…

Most ReLU Networks Suffer from $\ell^2$ Adversarial Perturbations

2020-10-28 · NeurIPS 2020 12 · Amit Daniely, Hadas Schacham

We consider ReLU networks with random weights, in which the dimension decreases at each layer. We show that for most such networks, most examples $x$ admit an adversarial perturbation at an Euclidean distance of $O\left(…

Fight Perturbations with Perturbations: Defending Adversarial Attacks via Neuron Influence

2021-12-24 · Ruoxi Chen, Haibo Jin, Haibin Zheng, Jinyin Chen 외

The vulnerabilities of deep learning models towards adversarial attacks have attracted increasing attention, especially when models are deployed in security-critical domains. Numerous defense methods, including reactive …

2D-Malafide: Adversarial Attacks Against Face Deepfake Detection Systems

2024-08-26 · Chiara Galdi, Michele Panariello, Massimiliano Todisco, Nicholas Evans

We introduce 2D-Malafide, a novel and lightweight adversarial attack designed to deceive face deepfake detection systems. Building upon the concept of 1D convolutional perturbations explored in the speech domain, our met…

Adversarial AttackDeepFake DetectionFace Swapping