BriefGPT.xyz
Dec, 2022
REAP:大规模真实对抗贴片基准测试
REAP: A Large-Scale Realistic Adversarial Patch Benchmark
HTML
PDF
Nabeel Hingun, Chawin Sitawarin, Jerry Li, David Wagner
TL;DR
该研究提出了一个数字基准(REAP)使用户能够在实际图像及真实情况下评估补丁攻击,通过实验证明补丁攻击可能比以前认为的威胁较小,而在简单的数字模拟下的攻击成功率并不预测其在实践中的实际效果。
Abstract
Machine learning models are known to be susceptible to
adversarial perturbation
. One famous attack is the
adversarial patch
, a sticker with a particularly crafted pattern that makes the model incorrectly predict
→