2017/05/20 by Nicholas Carlini, David Wagner, Carlini, Nicholas +1 · 335 citations
Computer Science · #Adversarial Robustness in Machine Learning #Adversarial system #Artificial intelligence #Artificial neural network #Computer Vision and Pattern Recognition (cs.CV) #Computer science #Cryptography and Security (cs.CR) #Deep neural networks #Economics #Epistemology #Explainable Artificial Intelligence (XAI) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Machine learning #Order (exchange) #Philosophy #Simple (philosophy) #Space (punctuation) #cs.CR #cs.CV #cs.LG
paper · pdf · doi:10.48550/arxiv.1705.07263
published in arXiv (Cornell University) (Cornell University)
openalex publication_date 2017/05/20 · arxiv created 2017/11/01 · arxiv updated 2017/11/02 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Neural networks are known to be vulnerable to adversarial examples: inputs that are close to natural inputs but classified incorrectly. In order to better understand the space of adversarial examples, we survey ten recent proposals that are designed for detection and compare their efficacy. We show that all can be defeated by constructing new loss functions. We conclude that adversarial examples are significantly harder to detect than previously appreciated, and the properties believed to be intrinsic to adversarial examples are in fact not. Finally, we propose several simple guidelines for evaluating future proposed defenses.