Understanding Adversarial Examples From the Mutual Influence of Images and Perturbations
Chaoning Zhang, Philipp Benz, Tooba Imtiaz, In So Kweon
Abstract
A wide variety of works have explored the reason for the existence of adversarial examples, but there is no consensus on the explanation. We propose to treat the DNN logits as a vector for feature representation, and exploit them to analyze the mutual influence of two independent inputs based on the Pearson correlation coefficient (PCC). We utilize this vector representation to understand adversarial examples by disentangling the clean images and adversarial perturbations, and analyze their influence on each other. Our results suggest a new perspective towards the relationship between images and universal perturbations: Universal perturbations contain dominant features, and images behave like noise to them. This feature perspective leads to a new method for generating targeted universal adversarial perturbations using random source images. We are the first to achieve the challenging task of a targeted universal attack without utilizing original training data. Our approach using a proxy dataset achieves comparable performance to the state-of-the-art baselines which utilize the original training dataset.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 986c51aa-ef92-4e1e-b9a3-3d4ee1d0902bCited by top-tier papers30
- UDH: Universal Deep Hiding for Steganography, Watermarking, and Light Field MessagingChaoning Zhang, Philipp Benz, Adil Karjauv, Geng Sun et al.NeurIPS 2020 · 198 citations
- On Success and Simplicity: A Second Look at Transferable Targeted AttacksZhengyu Zhao, Zhuoran Liu, Martha A. LarsonNeurIPS 2021 · 173 citations
- Data-free Universal Adversarial Perturbation and Black-box AttackChaoning Zhang, Philipp Benz, Adil Karjauv, In So KweonICCV 2021 · 83 citations
- Universal Adversarial Perturbations Through the Lens of Deep Steganography: Towards a Fourier PerspectiveChaoning Zhang, Philipp Benz, Adil Karjauv, In So KweonAAAI 2021 · 50 citations
- Batch Normalization Increases Adversarial Vulnerability and Decreases Adversarial Transferability: A Non-Robust Feature PerspectivePhilipp Benz, Chaoning Zhang, In So KweonICCV 2021 · 47 citations
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Attacking Optical FlowAnurag Ranjan, Joel Janai, Andreas Geiger, Michael J. BlackICCV 2019 · 93 citations
- CD-UAP: Class Discriminative Universal Adversarial PerturbationChaoning Zhang, Philipp Benz, Tooba Imtiaz, In-So KweonAAAI 2020 · 64 citations
- Once a MAN: Towards Multi-Target Attack via Learning Multi-Target Adversarial Network OnceJiangfan Han, Xiaoyi Dong, Ruimao Zhang, Dongdong Chen et al.ICCV 2019 · 31 citations
Related papers
- Interpreting Attributions and Interactions of Adversarial AttacksXin Wang, Shuyun Lin, Hao Zhang, Yufei Zhu et al.ICCV 2021 · 20 citations
- Distilling Robust and Non-Robust Features in Adversarial Examples by Information BottleneckJunho Kim, Byung-Kwan Lee, Yong Man RoNeurIPS 2021 · 57 citations
- Towards a Unified Game-Theoretic View of Adversarial Perturbations and RobustnessJie Ren, Die Zhang, Yisen Wang, Lu Chen et al.NeurIPS 2021 · 27 citations
- Evaluations and Methods for Explanation through Robustness AnalysisCheng-Yu Hsieh, Chih-Kuan Yeh, Xuanqing Liu, Pradeep Kumar Ravikumar et al.ICLR 2021 · 68 citations
- Learning Universal Adversarial Perturbation by Adversarial ExampleMaosen Li, Yanhua Yang, Kun Wei, Xu Yang et al.AAAI 2022 · 44 citations
