REVIEW 2 cited by
Advances in adversarial attacks and defenses in computer vision: A survey
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Deep Learning (DL) is the most widely used tool in the contemporary field of computer vision. Its ability to accurately solve complex problems is employed in vision research to learn deep neural models for a variety of tasks, including security critical applications. However, it is now known that DL is vulnerable to adversarial attacks that can manipulate its predictions by introducing visually imperceptible perturbations in images and videos. Since the discovery of this phenomenon in 2013~[1], it has attracted significant attention of researchers from multiple sub-fields of machine intelligence. In [2], we reviewed the contributions made by the computer vision community in adversarial attacks on deep learning (and their defenses) until the advent of year 2018. Many of those contributions have inspired new directions in this area, which has matured significantly since witnessing the first generation methods. Hence, as a legacy sequel of [2], this literature review focuses on the advances in this area since 2018. To ensure authenticity, we mainly consider peer-reviewed contributions published in the prestigious sources of computer vision and machine learning research. Besides a comprehensive literature review, the article also provides concise definitions of technical terminologies for non-experts in this domain. Finally, this article discusses challenges and future outlook of this direction based on the literature reviewed herein and [2].
Forward citations
Cited by 2 Pith papers
-
Sequential Difference Maximization: Generating Adversarial Examples via Multi-Stage Optimization
SDM is a staged iterative attack whose DPDR loss sequentially raises the maximum non-true class probability, beating PGD, APGD, C&W, and AutoAttack on CIFAR-10/100 WideResNet defenses.
-
The Relationship Between Network Similarity and Transferability of Adversarial Attacks
Similarity between CNN architectures does not robustly predict transferred adversarial attack success, and the reported high-accuracy decision-tree predictor likely relies on a data-splitting artifact.
Discussion (0). Continue with ORCID to comment.