Keyword [Adversarial Patch]
Karmon D, Zoran D, Goldberg Y. Lavan: Localized and visible adversarial noise[J]. arXiv preprint arXiv:1801.02608, 2018.
1. Overview
In this paper, it proposed a algorithm to generate adversarial patches
- without covering the main objects of images
- only covering 2% of the pixels
- transferable across images and locations
- fool InceptionV3 model
1.1. Methods
1.1.1. Loss Function
1.1.2. To be Universal
- At each iteration, choose a random image x