Semi-Universal Adversarial Perturbations - Archive ouverte HAL Accéder directement au contenu
Pré-Publication, Document De Travail (Preprint/Prepublication) Année : 2023

Semi-Universal Adversarial Perturbations

Jordan Frecon
  • Fonction : Auteur
  • PersonId : 1090292
  • IdRef : 196503922
Paul Viallard
Emilie Morvant
Gilles Gasso
Amaury Habrard

Résumé

This paper introduces semi-universal perturbations that bridge the gap between specific and universal adversarial perturbations. The original idea is to craft a specific perturbation by choosing it among a set of $L$ universal perturbations. We propose to jointly learn the perturbations of this set to maximize the chances to attack each example by allowing it to choose its own perturbation. To do so, we derive an algorithm, with convergence guarantees under Lipschitz continuity assumptions. Semi-universal perturbations offer a better flexibility, interpretability and diversity, confirmed by our experiments. Additionally, we provide a generalization bound on the abilities of the perturbations to attack new examples.

Mots clés

Fichier principal
Vignette du fichier
suap_hal.pdf (587.59 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Licence : CC BY NC ND - Paternité - Pas d'utilisation commerciale - Pas de modification

Dates et versions

hal-03615461 , version 1 (21-03-2022)
hal-03615461 , version 2 (07-06-2023)

Identifiants

  • HAL Id : hal-03615461 , version 2

Citer

Jordan Frecon, Paul Viallard, Emilie Morvant, Gilles Gasso, Amaury Habrard, et al.. Semi-Universal Adversarial Perturbations. 2023. ⟨hal-03615461v2⟩
129 Consultations
167 Téléchargements

Partager

Gmail Facebook X LinkedIn More