A Survey On Universal Adversarial Attack
arXiv:2103.01498 · doi:10.24963/ijcai.2021/635
Abstract
The intriguing phenomenon of adversarial examples has attracted significant attention in machine learning and what might be more surprising to the community is the existence of universal adversarial perturbations (UAPs), i.e. a single perturbation to fool the target DNN for most images. With the focus on UAP against deep classifiers, this survey summarizes the recent progress on universal adversarial attacks, discussing the challenges from both the attack and defense sides, as well as the reason for the existence of UAP. We aim to extend this work as a dynamic survey that will regularly update its content to follow new works regarding UAP or universal attack in a wide range of domains, such as image, audio, video, text, etc. Relevant updates will be discussed at: https://bit.ly/2SbQlLG. We welcome authors of future works in this field to contact us for including your new finding.
Accepted by IJCAI 2021, survey track: https://www.ijcai.org/proceedings/2021/635
References in corpus (8)
- Fast is better than free: Revisiting adversarial training
- Robustness of classifiers: from adversarial to random noise
- Fast Feature Fool: A data independent approach to universal adversarial perturbations
- Transferable Universal Adversarial Perturbations Using Generative Models
- Real-time, Universal, and Robust Adversarial Attacks Against Speaker Recognition Systems
- Universal Adversarial Perturbation for Text Classification
- A Method for Computing Class-wise Universal Adversarial Perturbations
- Fast-UAP: An Algorithm for Speeding up Universal Adversarial Perturbation Generation with Orientation of Perturbation Vectors