Visualizing One Pixel Attack Using Adversarial Maps

Wanyi Wang, Jian Sun, Gang Wang

科研成果: 书/报告/会议事项章节会议稿件同行评审

6 引用 (Scopus)

摘要

One pixel attack is one of the most puzzling adversarial attacks, in which the position of the attack plays an important role. However, little research has been conducted on the distributions of one pixel attack. In this context, a technique called adversarial maps is proposed, which helps visualize the distributions of one pixel attack for the first time. Adversarial maps consist of pixel adversarial maps and probability adversarial maps, which record the pixel changes and the confidence of the target class in successful attack cases, respectively. Leveraging this technique, one pixel attack distributions and why the position of one pixel attack impacts success rate is explored. Adversarial maps reveal that successful attacks always group as regions and the high saliency areas of saliency maps are more likely to be attacked successfully. Moreover, these observations are further corroborated by a mathematical analysis, demonstrating that adversarial attacks are disturbances in the saliency maps.

源语言英语
主期刊名Proceedings - 2020 Chinese Automation Congress, CAC 2020
出版商Institute of Electrical and Electronics Engineers Inc.
924-929
页数6
ISBN(电子版)9781728176871
DOI
出版状态已出版 - 6 11月 2020
活动2020 Chinese Automation Congress, CAC 2020 - Shanghai, 中国
期限: 6 11月 20208 11月 2020

出版系列

姓名Proceedings - 2020 Chinese Automation Congress, CAC 2020

会议

会议2020 Chinese Automation Congress, CAC 2020
国家/地区中国
Shanghai
时期6/11/208/11/20

指纹

探究 'Visualizing One Pixel Attack Using Adversarial Maps' 的科研主题。它们共同构成独一无二的指纹。

引用此