arXiv · 2012.04692
Locally optimal detection of stochastic targeted universal adversarial perturbations
Abstract
Deep learning image classifiers are known to be vulnerable to small adversarial perturbations of input images. In this paper, we derive the locally optimal generalized likelihood ratio test (LO-GLRT) based detector for detecting stochastic targeted universal adversarial perturbations (UAPs) of the classifier inputs. We also describe a supervised training method to learn the detector's parameters, and demonstrate better performance of the detector compared to other detection methods on several popular image classification datasets.
Explore related subjects
Keep this discovery
Amish Goel, Pierre Moulin. 2020-12-08. Locally optimal detection of stochastic targeted universal adversarial perturbations. https://arxiv.org/abs/2012.04692
Cite the original work for its findings. Save a collection to share your selection of sources.