Understanding Adversarial Examples From the Mutual Influence of Images and Perturbations
Chaoning Zhang, Philipp Benz, Tooba Imtiaz, In So Kweon
摘要
A wide variety of works have explored the reason for the existence of adversarial examples, but there is no consensus on the explanation. We propose to treat the DNN logits as a vector for feature representation, and exploit them to analyze the mutual influence of two independent inputs based on the Pearson correlation coefficient (PCC). We utilize this vector representation to understand adversarial examples by disentangling the clean images and adversarial perturbations, and analyze their influence on each other. Our results suggest a new perspective towards the relationship between images and universal perturbations: Universal perturbations contain dominant features, and images behave like noise to them. This feature perspective leads to a new method for generating targeted universal adversarial perturbations using random source images. We are the first to achieve the challenging task of a targeted universal attack without utilizing original training data. Our approach using a proxy dataset achieves comparable performance to the state-of-the-art baselines which utilize the original training dataset.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper30
- UDH: Universal Deep Hiding for Steganography, Watermarking, and Light Field MessagingChaoning Zhang, Philipp Benz, Adil Karjauv, Geng Sun 等NeurIPS 2020 · 被引用 198 次
- On Success and Simplicity: A Second Look at Transferable Targeted AttacksZhengyu Zhao, Zhuoran Liu, Martha A. LarsonNeurIPS 2021 · 被引用 173 次
- Data-free Universal Adversarial Perturbation and Black-box AttackChaoning Zhang, Philipp Benz, Adil Karjauv, In So KweonICCV 2021 · 被引用 83 次
- Universal Adversarial Perturbations Through the Lens of Deep Steganography: Towards a Fourier PerspectiveChaoning Zhang, Philipp Benz, Adil Karjauv, In So KweonAAAI 2021 · 被引用 50 次
- Batch Normalization Increases Adversarial Vulnerability and Decreases Adversarial Transferability: A Non-Robust Feature PerspectivePhilipp Benz, Chaoning Zhang, In So KweonICCV 2021 · 被引用 47 次
它引用的顶会 Paper4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Attacking Optical FlowAnurag Ranjan, Joel Janai, Andreas Geiger, Michael J. BlackICCV 2019 · 被引用 93 次
- CD-UAP: Class Discriminative Universal Adversarial PerturbationChaoning Zhang, Philipp Benz, Tooba Imtiaz, In-So KweonAAAI 2020 · 被引用 64 次
- Once a MAN: Towards Multi-Target Attack via Learning Multi-Target Adversarial Network OnceJiangfan Han, Xiaoyi Dong, Ruimao Zhang, Dongdong Chen 等ICCV 2019 · 被引用 31 次
相关 Paper
- Interpreting Attributions and Interactions of Adversarial AttacksXin Wang, Shuyun Lin, Hao Zhang, Yufei Zhu 等ICCV 2021 · 被引用 20 次
- Distilling Robust and Non-Robust Features in Adversarial Examples by Information BottleneckJunho Kim, Byung-Kwan Lee, Yong Man RoNeurIPS 2021 · 被引用 57 次
- Towards a Unified Game-Theoretic View of Adversarial Perturbations and RobustnessJie Ren, Die Zhang, Yisen Wang, Lu Chen 等NeurIPS 2021 · 被引用 27 次
- Evaluations and Methods for Explanation through Robustness AnalysisCheng-Yu Hsieh, Chih-Kuan Yeh, Xuanqing Liu, Pradeep Kumar Ravikumar 等ICLR 2021 · 被引用 68 次
- Learning Universal Adversarial Perturbation by Adversarial ExampleMaosen Li, Yanhua Yang, Kun Wei, Xu Yang 等AAAI 2022 · 被引用 44 次
