A General Framework for Adversarial Examples with Objectives
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. Reiter · ACM Transactions on Privacy and Security · 2019
Images perturbed subtly to be misclassified by neural networks, calledadversarial examples, have emerged as a technically deep challenge and an important concern for several application domains. Most research on adversarial examples takes as its only constraint that the perturbed images are similar to the originals. However, real-world application of these ideas often requires the examples to satisfy additional objectives, which are typically enforced through custom modifications of the perturbation process. In this article, we proposeadversarial generative nets(AGNs), a general methodology to train ageneratorneural network to emit adversarial examples satisfying desired objectives. We demonstrate the ability of AGNs to accommodate a wide range of objectives, including imprecise ones difficult to model, in two application domains. In particular, we demonstratephysicaladversarial examples—eyeglass frames designed to fool face recognition—with better robustness, inconspicuousness, and scalability than previous approaches, as well as a new attack to fool a handwritten-digit classifier.