[论文阅读笔记]One pixel attack for foo
2020-03-29 本文已影响0人
wangxiaoguang
论文题目:One pixel attack for fooling deep neural networks
论文地址:https://arxiv.org/abs/1710.08864
One-pixel
The goal of adversaries in the case of targeted attacks is to find the optimized solution for the following question:
data:image/s3,"s3://crabby-images/d8820/d882058fed25eb196257c77b405541a2d0a4cf19" alt=""
where
-
, n-dimensional inputs
-
, the target image classifier
-
, the probability of
belonging to the class
-
, an additive adversarial perturbation according to
-
, the target class
-
, the limitation of maximum modification
In our approach, the equation is slightly different:
data:image/s3,"s3://crabby-images/010cb/010cb8d90fe0c27a91e51283d07a98d2f5f58116" alt=""
where is a small number. In the case of one-pixel attack
.
note: 0范数表示向量中非零元素的个数。
参考
One pixel 对抗攻击_学习笔记
修改一个像素,就能让神经网络识别图像出错
论文阅读笔记三十:One pixel attack for fooling deep neural networks(CVPR2017)