DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks
DeepFool: простой и точный метод обмана глубоких нейронных сетей
2016-06-01
SCID: 54.1/mdqztbfa
Discuss with AI
DeepFooladversarial perturbationsfooling deep neural networksimage classificationrobustness of deep classifiers
Figures from the paper
Abstract (AI)
State-of-the-art deep neural networks have achieved impressive results on many image classification tasks. However, these same architectures have been shown to be unstable to small, well sought, perturbations of the images. Despite the importance of this phenomenon, no effective methods have been proposed to accurately compute the robustness of state-of-the-art deep classifiers to such perturbations on large-scale datasets. In this paper, we fill this gap and propose the DeepFool algorithm to efficiently compute perturbations that fool deep networks, and thus reliably quantify the robustness of these classifiers. Extensive experimental results show that our approach outperforms recent methods in the task of computing adversarial perturbations and making classifiers more robust.
Key Findings
1
DeepFool enables reliable quantification of the robustness of state-of-the-art deep classifiers to small adversarial perturbations on large-scale datasets.
2
DeepFool is a proposed algorithm that efficiently computes minimal perturbations that fool deep neural networks.
3
Extensive experiments show DeepFool outperforms recent methods for computing adversarial perturbations.
4
Using DeepFool to compute adversarial perturbations can be used to make classifiers more robust.
Research Object
State-of-the-art deep neural network image classifiers
Research Subject
Computation of minimal adversarial perturbations and quantification of classifier robustness (ability to be fooled) using the DeepFool algorithm
Publication Details
Publication Date
2016-06-01
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest