English

LaVAN: Localized and Visible Adversarial Noise

Computer Vision and Pattern Recognition 2018-03-02 v2 Machine Learning

Abstract

Most works on adversarial examples for deep-learning based image classifiers use noise that, while small, covers the entire image. We explore the case where the noise is allowed to be visible but confined to a small, localized patch of the image, without covering any of the main object(s) in the image. We show that it is possible to generate localized adversarial noises that cover only 2% of the pixels in the image, none of them over the main object, and that are transferable across images and locations, and successfully fool a state-of-the-art Inception v3 model with very high success rates.

Keywords

Cite

@article{arxiv.1801.02608,
  title  = {LaVAN: Localized and Visible Adversarial Noise},
  author = {Danny Karmon and Daniel Zoran and Yoav Goldberg},
  journal= {arXiv preprint arXiv:1801.02608},
  year   = {2018}
}
R2 v1 2026-06-22T23:39:38.405Z