Synthesizing Robust Adversarial Examples Anish Athalye*, Logan - - PowerPoint PPT Presentation

synthesizing robust adversarial examples
SMART_READER_LITE
LIVE PREVIEW

Synthesizing Robust Adversarial Examples Anish Athalye*, Logan - - PowerPoint PPT Presentation

Synthesizing Robust Adversarial Examples Anish Athalye*, Logan Engstrom*, Andrew Ilyas*, Kevin Kwok Standard Adversarial Examples Given image x ; target class y Maximize with projected gradient descent: Standard Adversarial Examples Standard


slide-1
SLIDE 1

Synthesizing Robust Adversarial Examples

Anish Athalye*, Logan Engstrom*, Andrew Ilyas*, Kevin Kwok

slide-2
SLIDE 2

Standard Adversarial Examples

Given image x; target class y Maximize with projected gradient descent:

slide-3
SLIDE 3

Standard Adversarial Examples

slide-4
SLIDE 4

Standard Adversarial Examples

slide-5
SLIDE 5

Standard Adversarial Examples

Given image x; target class y Maximize with projected gradient descent: What happens when we transform the images?

slide-6
SLIDE 6

Standard Examples are Fragile

slide-7
SLIDE 7

Robust Adversarial Examples

Given image x; target class y; distribution of transformations T Maximize expectation over transformation: What happens when we transform the images?

slide-8
SLIDE 8

Robust Adversarial Examples

slide-9
SLIDE 9

Implementation

Euclidean LAB distance: Lagrangian Relaxation: Law of Large Numbers:

slide-10
SLIDE 10

Results

slide-11
SLIDE 11

Scaling EOT to 3D

Bundle everything into the transformation:

  • 3D rendering
  • 3D rotation
  • Perspective projection
  • Lighting
  • Noise
slide-12
SLIDE 12
slide-13
SLIDE 13

Challenges

  • Implementing a differentiable renderer
  • Modeling 3D printer color inaccuracy
  • Approximating physical phenomena
  • Choosing parameters of distribution
slide-14
SLIDE 14
slide-15
SLIDE 15

Demo