{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/semantic-adversarial-attacks-parametric","title":"Semantic Adversarial Attacks: Parametric Transformations That Fool Deep Classifiers","arxiv_id":"1904.08489","date":"2019-04-17","proceeding":"ICCV 2019 10","authors":["Ameya Joshi","Amitangshu Mukherjee","Soumik Sarkar","Chinmay Hegde"],"abstract":"Deep neural networks have been shown to exhibit an intriguing vulnerability to adversarial input images corrupted with imperceptible perturbations. However, the majority of adversarial attacks assume global, fine-grained control over the image pixel space. In this paper, we consider a different setting: what happens if the adversary could only alter specific attributes of the input image? These would generate inputs that might be perceptibly different, but still natural-looking and enough to fool a classifier. We propose a novel approach to generate such `semantic' adversarial examples by optimizing a particular adversarial loss over the range-space of a parametric conditional generative model. We demonstrate implementations of our attacks on binary classifiers trained on face images, and show that such natural-looking semantic adversarial examples exist. We evaluate the effectiveness of our attack on synthetic and real data, and present detailed comparisons with existing attack methods. We supplement our empirical results with theoretical bounds that demonstrate the existence of such parametric adversarial examples.","url_abs":"https://arxiv.org/abs/1904.08489v2","url_pdf":"https://arxiv.org/pdf/1904.08489v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"semantic-adversarial-attacks-parametric","repo_url":"https://github.com/ameya005/Semantic_Adversarial_Attacks","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1904.08489","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1904.08489"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/ameya005/Semantic_Adversarial_Attacks","reach":null}],"summary":{"ran_honours":1,"ran_violates":1,"unverified":2},"by_repo_kind":{"official":{"samples":4,"ran":2,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"7af9868987bd6174","entry":"get_abs_val","repo":"ameya005/Semantic_Adversarial_Attacks","repo_kind":"official","path":"attack_fadernets.py","file_url":"https://github.com/ameya005/Semantic_Adversarial_Attacks/blob/HEAD/attack_fadernets.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"7af9868987bd6174"}},{"code_sha256_prefix":"6d5acfb0087d1ee7","entry":"prod","repo":"ameya005/Semantic_Adversarial_Attacks","repo_kind":"official","path":"simple_classifier.py","file_url":"https://github.com/ameya005/Semantic_Adversarial_Attacks/blob/HEAD/simple_classifier.py","link_basis":"first_harvest_node","language":"python","status":"ran_violates","verification_level":1,"contract_check":"VIOLATES","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"6d5acfb0087d1ee7"}},{"code_sha256_prefix":"abbf22147fdaa2af","entry":"fgsm","repo":"ameya005/Semantic_Adversarial_Attacks","repo_kind":"official","path":"simple_classifier.py","file_url":"https://github.com/ameya005/Semantic_Adversarial_Attacks/blob/HEAD/simple_classifier.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"abbf22147fdaa2af"}},{"code_sha256_prefix":"e2dc3218a6608cc0","entry":"pgd","repo":"ameya005/Semantic_Adversarial_Attacks","repo_kind":"official","path":"simple_classifier.py","file_url":"https://github.com/ameya005/Semantic_Adversarial_Attacks/blob/HEAD/simple_classifier.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"e2dc3218a6608cc0"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}