Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Universal adversarial perturbations

About

Given a state-of-the-art deep neural network classifier, we show the existence of a universal (image-agnostic) and very small perturbation vector that causes natural images to be misclassified with high probability. We propose a systematic algorithm for computing universal perturbations, and show that state-of-the-art deep neural networks are highly vulnerable to such perturbations, albeit being quasi-imperceptible to the human eye. We further empirically analyze these universal perturbations and show, in particular, that they generalize very well across neural networks. The surprising existence of universal perturbations reveals important geometric correlations among the high-dimensional decision boundary of classifiers. It further outlines potential security breaches with the existence of single directions in the input space that adversaries can possibly exploit to break a classifier on most natural images.

Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, Pascal Frossard• 2016

Related benchmarks

TaskDatasetResultRank
Universal Targeted Adversarial AttackUnseen (test)
KMRa40.2
18
Universal Targeted Adversarial AttackSeen Samples (Used for Optimization) (train)
KMRa14.9
18
Adversarial AttackCityscapes (test)
ASR8.13
12
Adversarial AttackSA-1B (test)
ASR5.28
12
Adversarial AttackADE20K (test)
ASR1.62
11
Adversarial AttackCOCO (test)
ASR47
10
Attack Success RatePandaGPT Image Modality
Exact ASR0.00e+0
8
Attack Success RatePandaGPT Audio Modality
Exact ASR0.00e+0
3
Attack Success RatePandaGPT Text Modality
Exact ASR97
3
Showing 9 of 9 rows

Other info

Follow for update