Geometry-Inspired Top-K Adversarial Perturbations
Abstract
The brittleness of deep image classifiers to small adver-sarial input perturbations has been extensively studied inthe last several years. However, the main objective of ex-isting perturbations is primarily limited to change the cor-rectly predicted Top-1class by an incorrect one, which doesnot intend to change the Top-kprediction. In many digi-tal real-world scenarios Top-kprediction is more relevant.In this work, we propose a fast and accurate method ofcomputing Top-kadversarial examples as a simple multi-objective optimization. We demonstrate its efficacy andperformance by comparing it to other adversarial examplecrafting techniques. Moreover, based on this method, wepropose Top-kUniversal Adversarial Perturbations, image-agnostic tiny perturbations that cause the true class to beabsent among the Top-kprediction for the majority of nat-ural images. We experimentally show that our approachoutperforms baseline methods and even improves existingtechniques of finding Universal Adversarial Perturbations.
Cite
Text
Tursynbek et al. "Geometry-Inspired Top-K Adversarial Perturbations." Winter Conference on Applications of Computer Vision, 2022.Markdown
[Tursynbek et al. "Geometry-Inspired Top-K Adversarial Perturbations." Winter Conference on Applications of Computer Vision, 2022.](https://mlanthology.org/wacv/2022/tursynbek2022wacv-geometryinspired/)BibTeX
@inproceedings{tursynbek2022wacv-geometryinspired,
title = {{Geometry-Inspired Top-K Adversarial Perturbations}},
author = {Tursynbek, Nurislam and Petiushko, Aleksandr and Oseledets, Ivan},
booktitle = {Winter Conference on Applications of Computer Vision},
year = {2022},
pages = {3398-3407},
url = {https://mlanthology.org/wacv/2022/tursynbek2022wacv-geometryinspired/}
}