Adversarial Examples that Fool both Computer Vision and Time-Limited Humans
被引:0
|
作者:
Elsayed, Gamaleldin F.
论文数: 0引用数: 0
h-index: 0
机构:
Google Brain, Mountain View, CA USAGoogle Brain, Mountain View, CA USA
Elsayed, Gamaleldin F.
[1
]
Shankar, Shreya
论文数: 0引用数: 0
h-index: 0
机构:
Stanford Univ, Stanford, CA 94305 USAGoogle Brain, Mountain View, CA USA
Shankar, Shreya
[2
]
Cheung, Brian
论文数: 0引用数: 0
h-index: 0
机构:
Univ Calif Berkeley, Berkeley, CA USAGoogle Brain, Mountain View, CA USA
Cheung, Brian
[3
]
Papernot, Nicolas
论文数: 0引用数: 0
h-index: 0
机构:
Penn State Univ, University Pk, PA 16802 USAGoogle Brain, Mountain View, CA USA
Papernot, Nicolas
[4
]
Kurakin, Alexey
论文数: 0引用数: 0
h-index: 0
机构:
Google Brain, Mountain View, CA USAGoogle Brain, Mountain View, CA USA
Kurakin, Alexey
[1
]
Goodfellow, Ian
论文数: 0引用数: 0
h-index: 0
机构:
Google Brain, Mountain View, CA USAGoogle Brain, Mountain View, CA USA
Goodfellow, Ian
[1
]
Sohl-Dickstein, Jascha
论文数: 0引用数: 0
h-index: 0
机构:
Google Brain, Mountain View, CA USAGoogle Brain, Mountain View, CA USA
Sohl-Dickstein, Jascha
[1
]
机构:
[1] Google Brain, Mountain View, CA USA
[2] Stanford Univ, Stanford, CA 94305 USA
[3] Univ Calif Berkeley, Berkeley, CA USA
[4] Penn State Univ, University Pk, PA 16802 USA
来源:
ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 31 (NIPS 2018)
|
2018年
/
31卷
关键词:
MODELS;
D O I:
暂无
中图分类号:
TP18 [人工智能理论];
学科分类号:
081104 ;
0812 ;
0835 ;
1405 ;
摘要:
Machine learning models are vulnerable to adversarial examples: small changes to images can cause computer vision models to make mistakes such as identifying a school bus as an ostrich. However, it is still an open question whether humans are prone to similar mistakes. Here, we address this question by leveraging recent techniques that transfer adversarial examples from computer vision models with known parameters and architecture to other models with unknown parameters and architecture, and by matching the initial processing of the human visual system. We find that adversarial examples that strongly transfer across computer vision models influence the classifications made by time-limited human observers.