A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2020; you can also visit the original URL.
The file type is application/pdf
.
What if Adversarial Samples were Digital Images?
2020
Proceedings of the 2020 ACM Workshop on Information Hiding and Multimedia Security
Although adversarial sampling is a trendy topic in computer vision, very few works consider the integral constraint: The result of the attack is a digital image whose pixel values are integers. This is not an issue at first sight since applying a rounding after forging an adversarial sample trivially does the job. Yet, this paper shows theoretically and experimentally that this operation has a big impact. The adversarial perturbations are fragile signals whose quantization destroys its ability
doi:10.1145/3369412.3395062
dblp:conf/ih/BonnetFB20
fatcat:m2wila7l5jhjrmlk3ehz47mcaa