Sarial Examples with Spoofed Robustness Cer- Tificates

semanticscholar(2020)

引用 0|浏览2
暂无评分
摘要
To deflect adversarial attacks, a range of “certified” classifiers have been proposed. In addition to labeling an image, certified classifiers produce (when possible) a certificate guaranteeing that the input image is not an `p-bounded adversarial example. We present a new attack that exploits not only the labelling function of a classifier, but also the certificate generator. The proposed method applies large perturbations that place images far from a class boundary while maintaining the imperceptibility property of adversarial examples. The proposed “Shadow Attack” causes certifiably robust networks to mislabel an image and simultaneously produce a “spoofed” certificate of robustness.
更多
查看译文
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要