2015

Adversarial Manipulation of Deep Representations

Sabour, Sara, Cao, Yanshuai, Faghri, Fartash et al.

Understand

We show that the representation of an image in a deep neural network (DNN) can be manipulated to mimic those of other natural images, with only minor, imperceptible perturbations to the original image.

  • Previous methods for generating adversarial images focused on image perturbations designed to produce erroneous class labels, while we concentrate on the internal layers of DNN representations.
  • In this way our new class of adversarial images differs qualitatively from others.
  • While the adversary is perceptually similar to one image, its internal representation appears remarkably similar to a different image, one from a different class, bearing little if any apparent similarity to the input; they appear generic and consistent with the space of natural images.

Built on

  • Image quality assessment: From error visibility to structural similarity

    Wang, Z, Bovik, AC, Sheikh, HR, and Simoncelli, EP · 2004

    Earlier work this paper cites.

  • Imagenet: A large-scale hierarchical image database

    Deng, J, Dong, W, Socher, R, Li, LJ, Li, K, and Fei-Fei, L · 2009

    Earlier work this paper cites.

  • Deep sparse rectifier neural networks

    Glorot, X, Bordes, A, and Bengio, Y · 2011

    Earlier work this paper cites.

  • Imagenet classification with deep convolutional neural networks

    Krizhevsky, A, Sutskever, I, and Hinton, GE · 2012

    Earlier work this paper cites.

  • Return of the devil in the details: Delving deep into convolutional nets

    Chatfield, K., Simonyan, K., Vedaldi, A., and Zisserman, A · 2014

    Earlier work this paper cites.

Similar

Then

Beyond the bibliography

alphaXiv searches the wider corpus for related work and actual follow-ups.

Open on alphaXiv

alphaXiv is searching for related work…