English

Exploring the Space of Adversarial Images

Neural and Evolutionary Computing 2016-06-24 v5

Abstract

Adversarial examples have raised questions regarding the robustness and security of deep neural networks. In this work we formalize the problem of adversarial images given a pretrained classifier, showing that even in the linear case the resulting optimization problem is nonconvex. We generate adversarial images using shallow and deep classifiers on the MNIST and ImageNet datasets. We probe the pixel space of adversarial images using noise of varying intensity and distribution. We bring novel visualizations that showcase the phenomenon and its high variability. We show that adversarial images appear in large regions in the pixel space, but that, for the same task, a shallow classifier seems more robust to adversarial images than a deep convolutional network.

Keywords

Cite

@article{arxiv.1510.05328,
  title  = {Exploring the Space of Adversarial Images},
  author = {Pedro Tabacof and Eduardo Valle},
  journal= {arXiv preprint arXiv:1510.05328},
  year   = {2016}
}

Comments

Copyright 2016 IEEE. This manuscript was accepted at the IEEE International Joint Conference on Neural Networks (IJCNN) 2016. We will link the published version as soon as the DOI is available