Pith. sign in

REVIEW 1 cited by

Generative Adversarial Perturbations

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1712.02328 v3 pith:QMGTO2WP submitted 2017-12-06 cs.CV cs.CRcs.LGcs.NEstat.ML

classification cs.CVcs.CRcs.LGcs.NEstat.ML
keywords modelsperturbationsadversarialimagesachieveattacksfoolinggenerative
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

In this paper, we propose novel generative models for creating adversarial examples, slightly perturbed images resembling natural images but maliciously crafted to fool pre-trained models. We present trainable deep neural networks for transforming images to adversarial perturbations. Our proposed models can produce image-agnostic and image-dependent perturbations for both targeted and non-targeted attacks. We also demonstrate that similar architectures can achieve impressive results in fooling classification and semantic segmentation models, obviating the need for hand-crafting attack methods for each task. Using extensive experiments on challenging high-resolution datasets such as ImageNet and Cityscapes, we show that our perturbations achieve high fooling rates with small perturbation norms. Moreover, our attacks are considerably faster than current iterative methods at inference time.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Once a MAN: Towards Multi-Target Attack via Learning Multi-Target Adversarial Network Once

    cs.CV 2019-08 conditional novelty 5.0 of 10

    By feeding a one-hot target label into an encoder-decoder, a single MAN model can attack any ImageNet or CIFAR10 class and outperforms single-target generators in attack rate and transferability.

Pith tools