References & Citations
Computer Science > Computer Vision and Pattern Recognition
Title: Geometry-Inspired Top-k Adversarial Perturbations
(Submitted on 28 Jun 2020 (v1), last revised 23 Nov 2021 (this version, v6))
Abstract: The brittleness of deep image classifiers to small adversarial input perturbations has been extensively studied in the last several years. However, the main objective of existing perturbations is primarily limited to change the correctly predicted Top-1 class by an incorrect one, which does not intend to change the Top-k prediction. In many digital real-world scenarios Top-k prediction is more relevant. In this work, we propose a fast and accurate method of computing Top-k adversarial examples as a simple multi-objective optimization. We demonstrate its efficacy and performance by comparing it to other adversarial example crafting techniques. Moreover, based on this method, we propose Top-k Universal Adversarial Perturbations, image-agnostic tiny perturbations that cause the true class to be absent among the Top-k prediction for the majority of natural images. We experimentally show that our approach outperforms baseline methods and even improves existing techniques of finding Universal Adversarial Perturbations.
Submission history
From: Nurislam Tursynbek [view email][v1] Sun, 28 Jun 2020 18:05:57 GMT (5251kb,D)
[v2] Thu, 19 Nov 2020 09:25:38 GMT (5343kb,D)
[v3] Mon, 23 Nov 2020 03:54:29 GMT (5343kb,D)
[v4] Mon, 23 Aug 2021 03:02:07 GMT (3867kb,D)
[v5] Mon, 22 Nov 2021 16:23:38 GMT (3867kb,D)
[v6] Tue, 23 Nov 2021 14:58:22 GMT (3868kb,D)
Link back to: arXiv, form interface, contact.