UPSET 与 ANGRI:攻破高性能图像分类器
计算机视觉与模式识别
2017-07-06 v1
摘要
本文通过开发两种新颖的攻击方法实现了对高性能图像分类器的定向欺骗。第一种方法生成针对目标类别的通用扰动,第二种方法生成针对特定图像的扰动。我们在 MNIST 和 CIFAR10 数据集上进行了大量实验,以深入理解所提出的算法并展示其有效性。
引用
@article{arxiv.1707.01159,
title = {UPSET and ANGRI : Breaking High Performance Image Classifiers},
author = {Sayantan Sarkar and Ankan Bansal and Upal Mahbub and Rama Chellappa},
journal= {arXiv preprint arXiv:1707.01159},
year = {2017}
}