CVPR 2020
1 1 2,3 2 3 1,4 4
CVPR 2020 Universal Adversarial Attacks Image agnostic and - - PowerPoint PPT Presentation
1 1,4 2,3 2 3 4 1 CVPR 2020 Universal Adversarial Attacks Image agnostic and transferable across networks Adversarial No defense: Baseline DNN perturbation Input image Classification Feature extraction dense Perturbed image
1 1 2,3 2 3 1,4 4
Perturbed image
Adversarial perturbation Baseline DNN Vulture 33% Input image Baseline DNN Bald eagle 99% dense Predicted labels
RGB image Conv-1 feature maps Conv-2 feature maps Conv-3 feature maps Classification
dense
Frozen parameters from baseline DNN
Regenerated features
Feature Regeneration Unit
Ranked most susceptible features Ranked least susceptible features
Feature concat Feature Regeneration Unit Feature concat
Adversarial perturbation Input image Perturbed image Baseline DNN Baseline DNN Bald eagle 99% Proposed Defense Proposed Defense Bald eagle 99%
dense dense Predicted labels
Feature map
NAG GAP sPGD PD: croquet ball 77% FD: croquet ball 10% HGD: mixing bowl 30% Ours: ice cream 50% Ours: ice cream 83% Ours: ice cream 66% Perturbed image Adversarial noise Predictions Adversarial perturbation Input image Perturbed image Baseline DNN Baseline DNN Bald eagle 99% Bald eagle 99% Proposed Defense Proposed Defense