2016/10/26 by Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Moosavi-Dezfooli, Seyed-Mohsen +5 · 4 voices · 127 citations
Computer Science · Mathematics · #Adversarial Robustness in Machine Learning #Adversarial system #Anomaly Detection Techniques and Applications #Artificial intelligence #Artificial neural network #Classifier (UML) #Computer science #Computer security #Decision boundary #Deep neural networks #Domain Adaptation and Few-Shot Learning #Exploit #Perturbation (astronomy) #Physics #cs.AI #cs.CV #cs.LG #stat.ML
paper · pdf · doi:10.48550/arxiv.1610.08401
published in arXiv (Cornell University) (Cornell University) · Accepted at IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2017
openalex publication_date 2016/10/26 · arxiv created 2017/03/09 · arxiv updated 2017/03/10 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/05
Given a state-of-the-art deep neural network classifier, we show the existence of a universal (image-agnostic) and very small perturbation vector that causes natural images to be misclassified with high probability. We propose a systematic algorithm for computing universal perturbations, and show that state-of-the-art deep neural networks are highly vulnerable to such perturbations, albeit being quasi-imperceptible to the human eye. We further empirically analyze these universal perturbations and show, in particular, that they generalize very well across neural networks. The surprising existence of universal perturbations reveals important geometric correlations among the high-dimensional decision boundary of classifiers. It further outlines potential security breaches with the existence of single directions in the input space that adversaries can possibly exploit to break a classifier on most natural images.