Skip to main content
QUICK REVIEW

[Paper Review] Adversarial Examples - A Complete Characterisation of the Phenomenon

Alexandru Constantin Serban, Erik Poll|arXiv (Cornell University)|Oct 2, 2018
Adversarial Robustness in Machine Learning183 references44 citations
TL;DR

A comprehensive survey that characterizes adversarial examples, covering their existence, security implications, generation and defense methods, and transferability across models.

ABSTRACT

We provide a complete characterisation of the phenomenon of adversarial examples - inputs intentionally crafted to fool machine learning models. We aim to cover all the important concerns in this field of study: (1) the conjectures on the existence of adversarial examples, (2) the security, safety and robustness implications, (3) the methods used to generate and (4) protect against adversarial examples and (5) the ability of adversarial examples to transfer between different machine learning models. We provide ample background information in an effort to make this document self-contained. Therefore, this document can be used as survey, tutorial or as a catalog of attacks and defences using adversarial examples.

Motivation & Objective

  • Survey the existence and fundamental questions surrounding adversarial examples.
  • Explain security, safety, and robustness implications for machine learning systems.
  • Catalog and compare methods for generating adversarial examples and defending against them.
  • Examine the transferability of adversarial examples between different models and settings.
  • Provide self-contained background to serve as a tutorial, survey, or catalog of attacks and defenses.

Proposed method

  • Provide ample background to make the document self-contained.
  • Organize content into chapters addressing attack models, robustness, causes, attacks, defences, transferability, and distilled/defense techniques.
  • Catalog a wide range of attacks and defenses with contextual explanations.
  • Discuss theoretical and practical aspects of robustness and security in machine learning.
  • Reference a broad set of works to situate adversarial examples within the wider ML security landscape.

Experimental results

Research questions

  • RQ1What conjectures exist about the existence and nature of adversarial examples?
  • RQ2What are the security, safety, and robustness implications for machine learning systems?
  • RQ3What methods are used to generate adversarial examples and what defenses exist against them?
  • RQ4To what extent do adversarial examples transfer between different models and settings?

Key findings

  • The work provides a complete characterization of adversarial examples across theory, practice, and defense.
  • The document serves as a catalog of attacks and defenses, with a self-contained background for readers.
  • The survey covers transferability of adversarial examples between models and the robustness implications for security.
  • A wide range of related works and methods are organized to illustrate the landscape of adversarial ML.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.