{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/with-friends-like-these-who-needs-adversaries","title":"With Friends Like These, Who Needs Adversaries?","arxiv_id":"1807.04200","date":"2018-07-11","proceeding":"NeurIPS 2018 12","authors":["Saumya Jetley","Nicholas A. Lord","Philip H. S. Torr"],"abstract":"The vulnerability of deep image classification networks to adversarial attack\nis now well known, but less well understood. Via a novel experimental analysis,\nwe illustrate some facts about deep convolutional networks for image\nclassification that shed new light on their behaviour and how it connects to\nthe problem of adversaries. In short, the celebrated performance of these\nnetworks and their vulnerability to adversarial attack are simply two sides of\nthe same coin: the input image-space directions along which the networks are\nmost vulnerable to attack are the same directions which they use to achieve\ntheir classification performance in the first place. We develop this result in\ntwo main steps. The first uncovers the fact that classes tend to be associated\nwith specific image-space directions. This is shown by an examination of the\nclass-score outputs of nets as functions of 1D movements along these\ndirections. This provides a novel perspective on the existence of universal\nadversarial perturbations. The second is a clear demonstration of the tight\ncoupling between classification performance and vulnerability to adversarial\nattack within the spaces spanned by these directions. Thus, our analysis\nresolves the apparent contradiction between accuracy and vulnerability. It\nprovides a new perspective on much of the prior art and reveals profound\nimplications for efforts to construct neural nets that are both accurate and\nrobust to adversarial attack.","url_abs":"http://arxiv.org/abs/1807.04200v4","url_pdf":"http://arxiv.org/pdf/1807.04200v4.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"with-friends-like-these-who-needs-adversaries","repo_url":"https://github.com/torrvision/whoneedsadversaries","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"none","reach":{"status":"ok"}}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"classification-1","task_name":"Classification"},{"task_slug":"classification","task_name":"General Classification"},{"task_slug":"image-classification","task_name":"Image Classification"},{"task_slug":"image-classification","task_name":"image-classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1807.04200","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}