[论文阅读笔记]ADVERSARIAL EXAMPLES IN

2020-03-27  本文已影响0人  wangxiaoguang

论文题目:A DVERSARIAL EXAMPLES IN THE PHYSICAL WORLD
论文地址:https://arxiv.org/abs/1607.02533

BIM

\boldsymbol{X}_{0}^{a d v}=\boldsymbol{X}, \quad \boldsymbol{X}_{N+1}^{a d v}=\operatorname{Clip}_{X, \epsilon}\left\{\boldsymbol{X}_{N}^{a d v}+\alpha \operatorname{sign}\left(\nabla_{X} J\left(\boldsymbol{X}_{N}^{a d v}, y_{t r u e}\right)\right)\right\}
Clip表示剪辑图像(像素的值),\epsilon确保每一次剪辑后的像素值在原图像的\epsilon-neighbourhood中,实验中,\alpha=1

ILCM

\boldsymbol{X}_{0}^{a d v}=\boldsymbol{X}, \quad \boldsymbol{X}_{N+1}^{a d v}=\operatorname{Clip}_{X, \epsilon}\left\{\boldsymbol{X}_{N}^{a d v}-\alpha \operatorname{sign}\left(\nabla_{X} J\left(\boldsymbol{X}_{N}^{a d v}, y_{L L}\right)\right)\right\}
y_{LL}为最不可能类别的标签,这相当于目标攻击。

参考:

https://www.jianshu.com/p/2f3b15617236

上一篇下一篇

猜你喜欢

热点阅读