Adversarial Examples on Object Recognition: A Comprehensive Survey
arXiv:2008.04094
Abstract
Deep neural networks are at the forefront of machine learning research. However, despite achieving impressive performance on complex tasks, they can be very sensitive: Small perturbations of inputs can be sufficient to induce incorrect behavior. Such perturbations, called adversarial examples, are intentionally designed to test the network's sensitivity to distribution drifts. Given their surprisingly small size, a wide body of literature conjectures on their existence and how this phenomenon can be mitigated. In this article we discuss the impact of adversarial examples on security, safety, and robustness of neural networks. We start by introducing the hypotheses behind their existence, the methods used to construct or protect against them, and the capacity to transfer adversarial examples between different machine learning models. Altogether, the goal is to provide a comprehensive and self-contained survey of this growing field of research.
Published in ACM CSUR. arXiv admin note: text overlap with arXiv:1810.01185
References in corpus (24)
- Distilling the Knowledge in a Neural Network
- Sequence to Sequence Learning with Neural Networks
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- On Evaluating Adversarial Robustness
- The Space of Transferable Adversarial Examples
- Countering Adversarial Images using Input Transformations
- Security Evaluation of Pattern Classifiers under Attack
- Adversarial Machine Learning at Scale
- Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN
- A study of the effect of JPG compression on adversarial images
- Spatially Transformed Adversarial Examples
- Adversarial Transformation Networks: Learning to Generate Adversarial Examples
- On Detecting Adversarial Perturbations
- Measuring the tendency of CNNs to Learn Surface Statistical Regularities
- Simple Black-Box Adversarial Perturbations for Deep Networks
- MagNet and "Efficient Defenses Against Adversarial Attacks" are Not Robust to Adversarial Examples
- A Boundary Tilting Persepective on the Phenomenon of Adversarial Examples
- Biologically inspired protection of deep networks from adversarial attacks
- Exploring the Space of Black-box Attacks on Deep Neural Networks
- Adversarial Attacks on Neural Network Policies
- Standard detectors aren't (currently) fooled by physical adversarial stop signs
- Attacking Binarized Neural Networks
- HyperNetworks with statistical filtering for defending adversarial examples