4 ms·
What I would like to understand better is how transferable these adversarial images are from a network to another. I mean is the adversity "deep", like practica
by beefield 7y ago
What I would like to understand better is how transferable these adversarial images are from a network to another. I mean is the adversity "deep", like practically all models built on resnet18 (or even completely different models) suffer from the adveristy? Or is it "shallow", meaning just one more training round will mess up the special "gradient paths" found for these particular network weights?
- 1024core 7y agoThat is a good question. I'm not aware of someone exploring this avenue, but it would be interesting to see what categories of models are fooled by what types of noise.
- igorkraw 7y ago"Noise" is the wrong way to think about these IMO, while robustness to noise implies robustness to a degree of perturbations, the perturbations have clearly outlined "directions" which can be visualised via so called "church plots". Seyed-Mohsen Moosavi-Dezfooli http://smoosavi.me/ http://smoosavi.me/ and the lab of Prof. Frossard have done amazing work exploring this.
- JoeDaDude 7y agoNicholas Papernot [1] et al. has shown how this can be an attack on an unknown network provided you have access to inference results produced by the target network [2]. [1] https://www.papernot.fr/ https://www.papernot.fr/ [2] https://arxiv.org/abs/1602.02697 https://arxiv.org/abs/1602.02697
- igorkraw 7y agoThe adversity is not only "deep" in the sense that resnet are affected, it seems to be universal and intrinsically tied to accuracy of current classifiers. For reference look for "Empirically estimating concentration of measures: Fundamental limits to robustness", "Adversarial Examples are features, not bugs" and the work on transferability by Papernot, Athalye, Madry and others