preprint Open access

SmoothFool: An Efficient Framework for Computing Smooth Adversarial\n Perturbations

  • arXiv (Cornell University)
  • Cornell University
Research footprint

At a glance

Citations
0
References
0
Comments
0
Paper overview

Abstract

Deep neural networks are susceptible to adversarial manipulations in the\ninput domain. The extent of vulnerability has been explored intensively in\ncases of $\\ell_p$-bounded and $\\ell_p$-minimal adversarial perturbations.\nHowever, the vulnerability of DNNs to adversarial perturbations with specific\nstatistical properties or frequency-domain characteristics has not been\nsufficiently explored. In this paper, we study the smoothness of perturbations\nand propose SmoothFool, a general and computationally efficient framework for\ncomputing smooth adversarial perturbations. Through extensive experiments, we\nvalidate the efficacy of the proposed method for both the white-box and\nblack-box attack scenarios. In particular, we demonstrate that: (i) there exist\nextremely smooth adversarial perturbations for well-established and widely used\nnetwork architectures, (ii) smoothness significantly enhances the robustness of\nperturbations against state-of-the-art defense mechanisms, (iii) smoothness\nimproves the transferability of adversarial perturbations across both data\npoints and network architectures, and (iv) class categories exhibit a variable\nrange of susceptibility to smooth perturbations. Our results suggest that\nsmooth APs can play a significant role in exploring the vulnerability extent of\nDNNs to adversarial examples.\n

Record transparency

Publication details

DOI
10.48550/arxiv.1910.03624
OpenAlex
W4297208592
Document type
preprint
Language
EN
Source
arXiv (Cornell University)
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.