【论文回顾】Towards Evaluating the Robustness of Neural Networks

paper notes:

1.this paper introduced three new attacks for L-0 L-2 L-infin distance metrics by defining different choices of objective function. Specifically, they are all based on the L-2 attack.

2.these attacks successfully beat defensive distillation. And high-confidence adv examples in a simple transferability also beat the defensive distillation.

they first summurize previous attack algorithms including L-BFGS, Fast Gradient Sign, JSMA, Deepfool.

And they tried different objective function and transform the optimization function.

and then give the three attacks:

L-2

L-0 L-infin are based on L-2.

they successfully applied attacks on distilled networks.

and also found that transferability works on the distilled network.

Strengths:

1.tried different objective function and applied by different metrics.

2.defeat defensive distillation networks by their attacks and high-confidence tranfered examples and preliminarily explain why previous attacks fail.

Detailed comments, possible improvements, or related ideas:

1. construct and evaluate a good distance metric to perfect measure of human perceptual similarity.

2. why all-black image was initially classified as 1 and all-white image was initially classified as 8

3. why fast gradient sign fails on defensive distillation after divide the logits by temperature T, where the authors said they cannot explain.

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值