English

Unrestricted Adversarial Attacks on ImageNet Competition

Computer Vision and Pattern Recognition 2021-10-27 v2

Abstract

Many works have investigated the adversarial attacks or defenses under the settings where a bounded and imperceptible perturbation can be added to the input. However in the real-world, the attacker does not need to comply with this restriction. In fact, more threats to the deep model come from unrestricted adversarial examples, that is, the attacker makes large and visible modifications on the image, which causes the model classifying mistakenly, but does not affect the normal observation in human perspective. Unrestricted adversarial attack is a popular and practical direction but has not been studied thoroughly. We organize this competition with the purpose of exploring more effective unrestricted adversarial attack algorithm, so as to accelerate the academical research on the model robustness under stronger unbounded attacks. The competition is held on the TianChi platform (\url{https://tianchi.aliyun.com/competition/entrance/531853/introduction}) as one of the series of AI Security Challengers Program.

Keywords

Cite

@article{arxiv.2110.09903,
  title  = {Unrestricted Adversarial Attacks on ImageNet Competition},
  author = {Yuefeng Chen and Xiaofeng Mao and Yuan He and Hui Xue and Chao Li and Yinpeng Dong and Qi-An Fu and Xiao Yang and Wenzhao Xiang and Tianyu Pang and Hang Su and Jun Zhu and Fangcheng Liu and Chao Zhang and Hongyang Zhang and Yichi Zhang and Shilong Liu and Chang Liu and Wenzhao Xiang and Yajie Wang and Huipeng Zhou and Haoran Lyu and Yidan Xu and Zixuan Xu and Taoyu Zhu and Wenjun Li and Xianfeng Gao and Guoqiu Wang and Huanqian Yan and Ying Guo and Chaoning Zhang and Zheng Fang and Yang Wang and Bingyang Fu and Yunfei Zheng and Yekui Wang and Haorong Luo and Zhen Yang},
  journal= {arXiv preprint arXiv:2110.09903},
  year   = {2021}
}

Comments

CVPR-2021 AIC Phase VI Track2: Unrestricted Adversarial Attacks on ImageNet

R2 v1 2026-06-24T07:00:21.758Z