arXiv · 2206.09075
Comment on Transferability and Input Transformation with Additive Noise
Abstract
Adversarial attacks have verified the existence of the vulnerability of neural networks. By adding small perturbations to a benign example, adversarial attacks successfully generate adversarial examples that lead misclassification of deep learning models. More importantly, an adversarial example generated from a specific model can also deceive other models without modification. We call this phenomenon ``transferability". Here, we analyze the relationship between transferability and input transformation with additive noise by mathematically proving that the modified optimization can produce more transferable adversarial examples.
Explore related subjects
Keep this discovery
Hoki Kim, Jinseong Park, Jaewook Lee. 2022-06-18. Comment on Transferability and Input Transformation with Additive Noise. https://arxiv.org/abs/2206.09075
Cite the original work for its findings. Save a collection to share your selection of sources.