Pith. sign in

REVIEW 2 cited by

Adversarial Examples in Deep Learning: Characterization and Divergence

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1807.00051 v3 pith:GRF7OZ3J submitted 2018-06-29 cs.LG stat.ML

classification cs.LGstat.ML
keywords adversarialdeeplearningdifferentattacksexamplesattackcharacterization
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

The burgeoning success of deep learning has raised the security and privacy concerns as more and more tasks are accompanied with sensitive data. Adversarial attacks in deep learning have emerged as one of the dominating security threat to a range of mission-critical deep learning systems and applications. This paper takes a holistic and principled approach to perform statistical characterization of adversarial examples in deep learning. We provide a general formulation of adversarial examples and elaborate on the basic principle for adversarial attack algorithm design. We introduce easy and hard categorization of adversarial attacks to analyze the effectiveness of adversarial examples in terms of attack success rate, degree of change in adversarial perturbation, average entropy of prediction qualities, and fraction of adversarial examples that lead to successful attacks. We conduct extensive experimental study on adversarial behavior in easy and hard attacks under deep learning models with different hyperparameters and different deep learning frameworks. We show that the same adversarial attack behaves differently under different hyperparameters and across different frameworks due to the different features learned under different deep learning model training process. Our statistical characterization with strong empirical evidence provides a transformative enlightenment on mitigation strategies towards effective countermeasures against present and future adversarial attacks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Denoising and Verification Cross-Layer Ensemble Against Black-box Adversarial Attacks

    cs.LG 2019-08 conditional novelty 6.0 of 10

    MODEF combines a denoising autoencoder ensemble with a verification model ensemble, using kappa diversity, to defend image classifiers against adversarial examples.

  2. Deep Neural Network Ensembles against Deception: Ensemble Diversity, Accuracy and Robustness

    cs.LG 2019-08 reject novelty 3.0 of 10

    Selecting DNN ensemble teams by low Kappa disagreement is presented as a defense against adversarial examples, but the evidence is preliminary and incomplete.

Pith tools