跳到主要导航 跳到搜索 跳到主要内容

Characterizing Adversarial Samples of Convolutional Neural Networks

  • Cheng Jiang
  • , Qiyang Zhao*
  • , Yuzhong Liu
  • *此作品的通讯作者
  • Beihang University
  • JD Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Adversarial samples aim to make deep convolutional neural networks predict incorrectly under small perturbations. This paper investigates non-targeted adversarial samples of convolutional neural networks and makes a primitive attempt to characterize adversarial samples. Two observations are made: first, adversarial perturbations are mainly in the high-frequency domain; second, adversarial categories usually have strong semantic relevance to the original categories. Our two observations provide a solid basis to understand the behavior of convolutional neural networks and thus to improve their robustness against adversarial samples.

源语言英语
主期刊名Proceedings - 2018 11th International Congress on Image and Signal Processing, BioMedical Engineering and Informatics, CISP-BMEI 2018
编辑Wei Li, Qingli Li, Lipo Wang
出版商Institute of Electrical and Electronics Engineers Inc.
ISBN(电子版)9781538676042
DOI
出版状态已出版 - 2 7月 2018
活动11th International Congress on Image and Signal Processing, BioMedical Engineering and Informatics, CISP-BMEI 2018 - Beijing, 中国
期限: 13 10月 201815 10月 2018

出版系列

姓名Proceedings - 2018 11th International Congress on Image and Signal Processing, BioMedical Engineering and Informatics, CISP-BMEI 2018

会议

会议11th International Congress on Image and Signal Processing, BioMedical Engineering and Informatics, CISP-BMEI 2018
国家/地区中国
Beijing
时期13/10/1815/10/18

指纹

探究 'Characterizing Adversarial Samples of Convolutional Neural Networks' 的科研主题。它们共同构成独一无二的指纹。

引用此