Fooling a neural network with common adversarial noise
Marko Mihajlović, Nikola Z. Popović · 2018
These days deep Neural Networks (NN) show exceptional performance on speech and visual recognition tasks. These systems are still considered a black box without deep understanding why they perform in such a manner. This lack of understanding makes NNs vulnerable to specially crafted adversarial examples - inputs with small perturbations that make the model misclassify. In this paper, we generated adversarial examples that will fool a NN used for classifying handwritten digits. We start by generating additive adversarial noise for each image. Afterwards, we propose an algorithm for crafting a single adversarial noise for misclassifying different members of the same class.