Understand
We show that the representation of an image in a deep neural network (DNN) can be manipulated to mimic those of other natural images, with only minor, imperceptible perturbations to the original image.
- Previous methods for generating adversarial images focused on image perturbations designed to produce erroneous class labels, while we concentrate on the internal layers of DNN representations.
- In this way our new class of adversarial images differs qualitatively from others.
- While the adversary is perceptually similar to one image, its internal representation appears remarkably similar to a different image, one from a different class, bearing little if any apparent similarity to the input; they appear generic and consistent with the space of natural images.
Built on
Image quality assessment: From error visibility to structural similarity
Wang, Z, Bovik, AC, Sheikh, HR, and Simoncelli, EP · 2004
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Deng, J, Dong, W, Socher, R, Li, LJ, Li, K, and Fei-Fei, L · 2009
Earlier work this paper cites.
Deep sparse rectifier neural networks
Glorot, X, Bordes, A, and Bengio, Y · 2011
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Krizhevsky, A, Sutskever, I, and Hinton, GE · 2012
Earlier work this paper cites.
Return of the devil in the details: Delving deep into convolutional nets
Chatfield, K., Simonyan, K., Vedaldi, A., and Zisserman, A · 2014
Earlier work this paper cites.
Similar
Explaining and harnessing adversarial examples
Goodfellow, IJ, Shlens, J, and Szegedy, C · 2014
Cited alongside, same era.
Towards deep neural network architectures robust to adversarial examples
Gu, S and Rigazio, L · 2014
Cited alongside, same era.
Caffe: Convolutional architecture for fast feature embedding
Jia, Y, Shelhamer, E, Donahue, J, Karayev, S, Long, J, Girshick, R, Guadarrama, S, and Darrell, T · 2014
Cited alongside, same era.
Understanding deep image representations by inverting them
Mahendran, A and Vedaldi, A · 2014
Cited alongside, same era.
Intriguing properties of neural networks
Szegedy, C, Zaremba, W, Sutskever, I, Bruna, J, Erhan, D, Goodfellow, I, and Fergus, R · 2014
Cited alongside, same era.
Then
Learning deep features for scene recognition using places database
Zhou, B, Lapedriza, A, Xiao, J, Torralba, A, and Oliva, A · 2014
Later among the works it cites.
Fundamental limits on adversarial robustness
Fawzi, A, Fawzi, O, and Frossard, P · 2015
Closest in time.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
Nguyen, A, Yosinski, J, and Clune, J · 2015
Closest in time.
Going deeper with convolutions
Szegedy, C, Liu, W, Jia, Y, Sermanet, P, Reed, S, Anguelov, D, Erhan, D, Vanhoucke, V, and Rabinovich, A · 2015
Closest in time.
Exploring the space of adversarial images
Tabacof, P and Valle, E · 2015
Closest in time.
Beyond the bibliography
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…