Pith. sign in

The Space of Transferable Adversarial Examples

9 Pith papers cite this work. Polarity classification is still indexing.

9 Pith papers citing it
abstract

Adversarial examples are maliciously perturbed inputs designed to mislead machine learning (ML) models at test-time. They often transfer: the same adversarial example fools more than one model. In this work, we propose novel methods for estimating the previously unknown dimensionality of the space of adversarial inputs. We find that adversarial examples span a contiguous subspace of large (~25) dimensionality. Adversarial subspaces with higher dimensionality are more likely to intersect. We find that for two different models, a significant fraction of their subspaces is shared, thus enabling transferability. In the first quantitative analysis of the similarity of different models' decision boundaries, we show that these boundaries are actually close in arbitrary directions, whether adversarial or benign. We conclude by formally studying the limits of transferability. We derive (1) sufficient conditions on the data distribution that imply transferability for simple model classes and (2) examples of scenarios in which transfer does not occur. These findings indicate that it may be possible to design defenses against transfer-based attacks, even for models that are vulnerable to direct attacks.

citation-role summary

background 1

citation-polarity summary

roles

background 1

polarities

background 1

representative citing papers

Towards Deep Learning Models Resistant to Adversarial Attacks

stat.ML · 2017-06-19 · accept · novelty 7.0

Adversarial training via projected gradient descent on the inner maximization problem produces neural networks with substantially improved resistance to a wide range of attacks and establishes security against first-order adversaries as a concrete guarantee.

Open DNN Box by Power Side-Channel Attack

cs.CR · 2019-07-21 · unverdicted · novelty 6.0

Power side-channel analysis recovers DNN architecture and parameters at 96.5% average accuracy on real embedded devices.

Fooling a Real Car with Adversarial Traffic Signs

cs.CR · 2019-06-30 · unverdicted · novelty 6.0

A reproducible pipeline produces physical adversarial traffic signs that successfully attack production-grade traffic sign recognition systems in a real car under black-box conditions.

Beneficial perturbation network for continual learning

cs.LG · 2019-06-22 · unverdicted · novelty 5.0

BPN adds task-specific beneficial perturbations as biases to neural networks to overcome catastrophic forgetting without storing prior data or expanding the network substantially.

citing papers explorer

Showing 9 of 9 citing papers.