Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
119 tokens/sec
GPT-4o
56 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
6 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Analyzing Adversarial Robustness of Deep Neural Networks in Pixel Space: a Semantic Perspective (2106.09872v1)

Published 18 Jun 2021 in cs.CV and physics.soc-ph

Abstract: The vulnerability of deep neural networks to adversarial examples, which are crafted maliciously by modifying the inputs with imperceptible perturbations to misled the network produce incorrect outputs, reveals the lack of robustness and poses security concerns. Previous works study the adversarial robustness of image classifiers on image level and use all the pixel information in an image indiscriminately, lacking of exploration of regions with different semantic meanings in the pixel space of an image. In this work, we fill this gap and explore the pixel space of the adversarial image by proposing an algorithm to looking for possible perturbations pixel by pixel in different regions of the segmented image. The extensive experimental results on CIFAR-10 and ImageNet verify that searching for the modified pixel in only some pixels of an image can successfully launch the one-pixel adversarial attacks without requiring all the pixels of the entire image, and there exist multiple vulnerable points scattered in different regions of an image. We also demonstrate that the adversarial robustness of different regions on the image varies with the amount of semantic information contained.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (7)
  1. Lina Wang (29 papers)
  2. Xingshu Chen (13 papers)
  3. Yulong Wang (58 papers)
  4. Yawei Yue (2 papers)
  5. Yi Zhu (233 papers)
  6. Xuemei Zeng (2 papers)
  7. Wei Wang (1793 papers)

Summary

We haven't generated a summary for this paper yet.