Smooth Adversarial Examples - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Pré-Publication, Document De Travail Année : 2019

Smooth Adversarial Examples

Résumé

This paper investigates the visual quality of the adver-sarial examples. Recent papers propose to smooth the perturbations to get rid of high frequency artefacts. In this work, smoothing has a different meaning as it perceptually shapes the perturbation according to the visual content of the image to be attacked. The perturbation becomes locally smooth on the flat areas of the input image, but it may be noisy on its textured areas and sharp across its edges. This operation relies on Laplacian smoothing, well-known in graph signal processing, which we integrate in the attack pipeline. We benchmark several attacks with and without smoothing under a white-box scenario and evaluate their transferability. Despite the additional constraint of smoothness, our attack has the same probability of success at lower distortion.
Fichier principal
Vignette du fichier
1903.11862.pdf (5.34 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02370202 , version 1 (19-11-2019)

Identifiants

Citer

Hanwei Zhang, Yannis Avrithis, Teddy Furon, Laurent Amsaleg. Smooth Adversarial Examples. 2019. ⟨hal-02370202⟩
74 Consultations
150 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More