(2018) LaVAN:Localized and Visible Adversarial Noise

Keyword [Adversarial Patch]

Karmon D, Zoran D, Goldberg Y. Lavan: Localized and visible adversarial noise[J]. arXiv preprint arXiv:1801.02608, 2018.

1. Overview

In this paper, it proposed a algorithm to generate adversarial patches

  • without covering the main objects of images
  • only covering 2% of the pixels
  • transferable across images and locations
  • fool InceptionV3 model

1.1. Methods

1.1.1. Loss Function

1.1.2. To be Universal

  • At each iteration, choose a random image x

1.2. Visualization