{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/distorting-neural-representations-to-generate","title":"Task-generalizable Adversarial Attack based on Perceptual Metric","arxiv_id":"1811.09020","date":"2018-11-22","proceeding":null,"authors":["Muzammal Naseer","Salman H. Khan","Shafin Rahman","Fatih Porikli"],"abstract":"Deep neural networks (DNNs) can be easily fooled by adding human\nimperceptible perturbations to the images. These perturbed images are known as\n`adversarial examples' and pose a serious threat to security and safety\ncritical systems. A litmus test for the strength of adversarial examples is\ntheir transferability across different DNN models in a black box setting (i.e.\nwhen the target model's architecture and parameters are not known to attacker).\nCurrent attack algorithms that seek to enhance adversarial transferability work\non the decision level i.e. generate perturbations that alter the network\ndecisions. This leads to two key limitations: (a) An attack is dependent on the\ntask-specific loss function (e.g. softmax cross-entropy for object recognition)\nand therefore does not generalize beyond its original task. (b) The adversarial\nexamples are specific to the network architecture and demonstrate poor\ntransferability to other network architectures. We propose a novel approach to\ncreate adversarial examples that can broadly fool different networks on\nmultiple tasks. Our approach is based on the following intuition: \"Perpetual\nmetrics based on neural network features are highly generalizable and show\nexcellent performance in measuring and stabilizing input distortions. Therefore\nan ideal attack that creates maximum distortions in the network feature space\nshould realize highly transferable examples\". We report extensive experiments\nto show how adversarial examples generalize across multiple networks for\nclassification, object detection and segmentation tasks.","url_abs":"http://arxiv.org/abs/1811.09020v3","url_pdf":"http://arxiv.org/pdf/1811.09020v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"distorting-neural-representations-to-generate","repo_url":"https://github.com/DentanJeremie/adversarialTransferts","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"Apache-2.0"}}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"object-detection","task_name":"Object Detection"},{"task_slug":"object-recognition","task_name":"Object Recognition"},{"task_slug":"object-detection-1","task_name":"object-detection"}],"methods":[{"method_slug":"softmax","method_name":"Softmax"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1811.09020","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}