Understanding Misclassifications by Attributes

10/15/2019
by   Sadaf Gulshad, et al.
27

In this paper, we aim to understand and explain the decisions of deep neural networks by studying the behavior of predicted attributes when adversarial examples are introduced. We study the changes in attributes for clean as well as adversarial images in both standard and adversarially robust networks. We propose a metric to quantify the robustness of an adversarially robust network against adversarial attacks. In a standard network, attributes predicted for adversarial images are consistent with the wrong class, while attributes predicted for the clean images are consistent with the true class. In an adversarially robust network, the attributes predicted for adversarial images classified correctly are consistent with the true class. Finally, we show that the ability to robustify a network varies for different datasets. For the fine grained dataset, it is higher as compared to the coarse-grained dataset. Additionally, the ability to robustify a network increases with the increase in adversarial noise.

READ FULL TEXT

page 3

page 6

page 7

research
04/17/2019

Interpreting Adversarial Examples with Attributes

Deep computer vision systems being vulnerable to imperceptible and caref...
research
07/13/2022

Adversarially-Aware Robust Object Detector

Object detection, as a fundamental computer vision task, has achieved a ...
research
05/30/2022

Exposing Fine-grained Adversarial Vulnerability of Face Anti-spoofing Models

Adversarial attacks seriously threaten the high accuracy of face anti-sp...
research
06/06/2023

Revisiting the Trade-off between Accuracy and Robustness via Weight Distribution of Filters

Adversarial attacks have been proven to be potential threats to Deep Neu...
research
06/10/2020

Towards Robust Fine-grained Recognition by Maximal Separation of Discriminative Features

Adversarial attacks have been widely studied for general classification ...
research
11/20/2019

Fine-grained Synthesis of Unrestricted Adversarial Examples

We propose a novel approach for generating unrestricted adversarial exam...
research
04/17/2017

Adversarial and Clean Data Are Not Twins

Adversarial attack has cast a shadow on the massive success of deep neur...

Please sign up or login with your details

Forgot password? Click here to reset