In this paper, targeted fooling of high performance image classifiers is achieved by developing two novel attack methods. The first method generates universal perturbations for target classes and the second generates image specific perturbations. Extensive experiments are conducted on MNIST and CIFAR10 datasets to provide insights about the proposed algorithms and show their effectiveness.
No takes yet. Share an insight, caveat, or question.
Sarkar et al. (2017) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: