Over the last decade, deep neural networks have achieved state of the art in computer vision tasks. These models, however, are susceptible to unusual inputs, known as adversarial examples, that cause them to misclassify or otherwise fail to detect objects. Here, we provide evidence that the increasing success of adversarial attacks is primarily due to increasing their size. We then demonstrate a method for generating the largest possible adversarial patch by building a adversarial pattern out of repeatable elements. This approach achieves a new state of the art in evading detection by YOLOv2 and YOLOv3. Finally, we present an experiment that fails to replicate the prior success of several attacks published in this field, and end with some comments on testing and reproducibility.
翻译:过去十年间,深度神经网络在计算机视觉任务中达到了最先进水平。然而,这些模型容易受到异常输入(即对抗性样本)的影响,导致其分类错误或无法检测目标。本文中,我们提供证据表明,对抗攻击成功率的持续提升主要源于攻击规模的增大。随后,我们展示了一种通过可重复元素构建对抗性图案来生成最大可能对抗补丁的方法。该方法在规避YOLOv2和YOLOv3检测方面达到了新的最优水平。最后,我们呈现了一项未能复现该领域已发表的若干攻击先前成功结果的实验,并针对测试与可复现性提出几点评论。