{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/fast-feature-fool-a-data-independent-approach","title":"Fast Feature Fool: A data independent approach to universal adversarial perturbations","arxiv_id":"1707.05572","date":"2017-07-18","proceeding":null,"authors":["Konda Reddy Mopuri","Utsav Garg","R. Venkatesh Babu"],"abstract":"State-of-the-art object recognition Convolutional Neural Networks (CNNs) are\nshown to be fooled by image agnostic perturbations, called universal\nadversarial perturbations. It is also observed that these perturbations\ngeneralize across multiple networks trained on the same target data. However,\nthese algorithms require training data on which the CNNs were trained and\ncompute adversarial perturbations via complex optimization. The fooling\nperformance of these approaches is directly proportional to the amount of\navailable training data. This makes them unsuitable for practical attacks since\nits unreasonable for an attacker to have access to the training data. In this\npaper, for the first time, we propose a novel data independent approach to\ngenerate image agnostic perturbations for a range of CNNs trained for object\nrecognition. We further show that these perturbations are transferable across\nmultiple network architectures trained either on same or different data. In the\nabsence of data, our method generates universal adversarial perturbations\nefficiently via fooling the features learned at multiple layers thereby causing\nCNNs to misclassify. Experiments demonstrate impressive fooling rates and\nsurprising transferability for the proposed universal perturbations generated\nwithout any training data.","url_abs":"http://arxiv.org/abs/1707.05572v1","url_pdf":"http://arxiv.org/pdf/1707.05572v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"fast-feature-fool-a-data-independent-approach","repo_url":"https://github.com/utsavgarg/fast-feature-fool","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"object-recognition","task_name":"Object Recognition"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1707.05572","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}