Pith. sign in

REVIEW 1 cited by

Adversarial Images for Variational Autoencoders

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1612.00155 v1 pith:YQGAVUNE submitted 2016-12-01 cs.NE cs.CVcs.LG

classification cs.NEcs.CVcs.LG
keywords adversarialautoencodersinputattackimagetargetclassifiersdistortion
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We investigate adversarial attacks for autoencoders. We propose a procedure that distorts the input image to mislead the autoencoder in reconstructing a completely different target image. We attack the internal latent representations, attempting to make the adversarial input produce an internal representation as similar as possible as the target's. We find that autoencoders are much more robust to the attack than classifiers: while some examples have tolerably small input distortion, and reasonable similarity to the target image, there is a quasi-linear trade-off between those aims. We report results on MNIST and SVHN datasets, and also test regular deterministic autoencoders, reaching similar conclusions in all cases. Finally, we show that the usual adversarial attack for classifiers, while being much easier, also presents a direct proportion between distortion on the input, and misdirection on the output. That proportionality however is hidden by the normalization of the output, which maps a linear layer into non-linear probabilities.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Adversarial Robustness of Bottleneck Injected Deep Neural Networks for Task-Oriented Communication

    cs.LG 2024-12 conditional novelty 5.0 of 10

    Shallow variational bottleneck compression is more vulnerable to adversarial attacks than deep variational bottleneck compression, and generative decoders widen the attack surface in task-oriented communication.

Pith tools