Understanding the One-Pixel Attack: Propagation Maps and Locality Analysis

Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we propose Propagation Maps which show the influence of the perturbation in each layer of the network. Propagation Maps reveal that even in extre...

Full description

Saved in:
Bibliographic Details
Published inarXiv.org
Main Authors Danilo Vasconcellos Vargas, Su, Jiawei
Format Paper
LanguageEnglish
Published Ithaca Cornell University Library, arXiv.org 08.02.2019
Subjects
Online AccessGet full text

Cover

Loading…
Abstract Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we propose Propagation Maps which show the influence of the perturbation in each layer of the network. Propagation Maps reveal that even in extremely deep networks such as Resnet, modification in one pixel easily propagates until the last layer. In fact, this initial local perturbation is also shown to spread becoming a global one and reaching absolute difference values that are close to the maximum value of the original feature maps in a given layer. Moreover, we do a locality analysis in which we demonstrate that nearby pixels of the perturbed one in the one-pixel attack tend to share the same vulnerability, revealing that the main vulnerability lies in neither neurons nor pixels but receptive fields. Hopefully, the analysis conducted in this work together with a new technique called propagation maps shall shed light into the inner workings of other adversarial samples and be the basis of new defense systems to come.
AbstractList Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we propose Propagation Maps which show the influence of the perturbation in each layer of the network. Propagation Maps reveal that even in extremely deep networks such as Resnet, modification in one pixel easily propagates until the last layer. In fact, this initial local perturbation is also shown to spread becoming a global one and reaching absolute difference values that are close to the maximum value of the original feature maps in a given layer. Moreover, we do a locality analysis in which we demonstrate that nearby pixels of the perturbed one in the one-pixel attack tend to share the same vulnerability, revealing that the main vulnerability lies in neither neurons nor pixels but receptive fields. Hopefully, the analysis conducted in this work together with a new technique called propagation maps shall shed light into the inner workings of other adversarial samples and be the basis of new defense systems to come.
Author Danilo Vasconcellos Vargas
Su, Jiawei
Author_xml – sequence: 1
  fullname: Danilo Vasconcellos Vargas
– sequence: 2
  givenname: Jiawei
  surname: Su
  fullname: Su, Jiawei
BookMark eNqNysEKgjAYAOARBVn5DoPOgv7TlG4SRUSRhzrL0GWzsdn-Cfn2eegBOn2Xb0Gm2mgxIR4wFgVZDDAnPmIbhiFsUkgS5pHTXdfCouO6lrqh7inoVYugkB-haO4cr15bWljT8YY7aTS98A7puOnZVFxJN9BcczWgxBWZPbhC4f9ckvVhf9sdg86ady_Qla3p7ZixhCjN4oQBhOy_9QX3Yj4Y
ContentType Paper
Copyright 2019. This work is published under http://arxiv.org/licenses/nonexclusive-distrib/1.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Copyright_xml – notice: 2019. This work is published under http://arxiv.org/licenses/nonexclusive-distrib/1.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
DBID 8FE
8FG
ABJCF
ABUWG
AFKRA
AZQEC
BENPR
BGLVJ
CCPQU
DWQXO
HCIFZ
L6V
M7S
PIMPY
PQEST
PQQKQ
PQUKI
PRINS
PTHSS
DatabaseName ProQuest SciTech Collection
ProQuest Technology Collection
Materials Science & Engineering Collection
ProQuest Central (Alumni)
ProQuest Central
ProQuest Central Essentials
ProQuest Central
Technology Collection
ProQuest One Community College
ProQuest Central
SciTech Premium Collection
ProQuest Engineering Collection
Engineering Database
Publicly Available Content Database
ProQuest One Academic Eastern Edition (DO NOT USE)
ProQuest One Academic
ProQuest One Academic UKI Edition
ProQuest Central China
Engineering Collection
DatabaseTitle Publicly Available Content Database
Engineering Database
Technology Collection
ProQuest Central Essentials
ProQuest One Academic Eastern Edition
ProQuest Central (Alumni Edition)
SciTech Premium Collection
ProQuest One Community College
ProQuest Technology Collection
ProQuest SciTech Collection
ProQuest Central China
ProQuest Central
ProQuest Engineering Collection
ProQuest One Academic UKI Edition
ProQuest Central Korea
Materials Science & Engineering Collection
ProQuest One Academic
Engineering Collection
DatabaseTitleList Publicly Available Content Database
Database_xml – sequence: 1
  dbid: 8FG
  name: ProQuest Technology Collection
  url: https://search.proquest.com/technologycollection1
  sourceTypes: Aggregation Database
DeliveryMethod fulltext_linktorsrc
Discipline Physics
EISSN 2331-8422
Genre Working Paper/Pre-Print
GroupedDBID 8FE
8FG
ABJCF
ABUWG
AFKRA
ALMA_UNASSIGNED_HOLDINGS
AZQEC
BENPR
BGLVJ
CCPQU
DWQXO
FRJ
HCIFZ
L6V
M7S
M~E
PIMPY
PQEST
PQQKQ
PQUKI
PRINS
PTHSS
ID FETCH-proquest_journals_21784532203
IEDL.DBID BENPR
IngestDate Tue Sep 24 19:57:20 EDT 2024
IsOpenAccess true
IsPeerReviewed false
IsScholarly false
Language English
LinkModel DirectLink
MergedId FETCHMERGED-proquest_journals_21784532203
OpenAccessLink https://www.proquest.com/docview/2178453220/abstract/?pq-origsite=%requestingapplication%
PQID 2178453220
PQPubID 2050157
ParticipantIDs proquest_journals_2178453220
PublicationCentury 2000
PublicationDate 20190208
PublicationDateYYYYMMDD 2019-02-08
PublicationDate_xml – month: 02
  year: 2019
  text: 20190208
  day: 08
PublicationDecade 2010
PublicationPlace Ithaca
PublicationPlace_xml – name: Ithaca
PublicationTitle arXiv.org
PublicationYear 2019
Publisher Cornell University Library, arXiv.org
Publisher_xml – name: Cornell University Library, arXiv.org
SSID ssj0002672553
Score 3.182967
SecondaryResourceType preprint
Snippet Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we...
SourceID proquest
SourceType Aggregation Database
SubjectTerms Feature maps
Neural networks
Pixels
Propagation
Title Understanding the One-Pixel Attack: Propagation Maps and Locality Analysis
URI https://www.proquest.com/docview/2178453220/abstract/
hasFullText 1
inHoldings 1
isFullTextHit
isPrint
link http://utb.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwfV1bS8MwFD5sK4JvXvEyR0BfQ9N754uodJZhZxEHextJmopMZm0r-ORv96S0Kgh7DAkhCYfznct3cgAuAsYz5XqC5og11LUYoyL3NNc1c5gM0SFQut45mfnx3J0uvEUP4q4WRtMqO53YKOrsTeoYuYmmc-h6KH7M5EJHAWRtXhXvVPeP0nnWtplGHwzbcnXC1riJZunjT7zF9gO0np1_KrfBkckOGCkvVLkLPbXeg62GfimrfZjO_9aYEDTKyMNa0fTlU72S67rmcnVJ0hId3OfmJUnCi4rganKvsQgtadL9LnIA55Po6Tam3QGWrbhUy9_LOYcwQL9fHQHxGFOZsmTAfdsVuc8ly2wxdkLFPMWC7BiGm3Y62Tx9CtuI_eOGgBwOYVCXH-oM8bUWI-iHk7tR-4A4Sr6ib6E3heg
link.rule.ids 786,790,12792,21416,33408,33779,43635,43840
linkProvider ProQuest
linkToHtml http://utb.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwfV3fS8MwED50Q_TNn_hjakBfg1mbtJ0vImKts5192GBvJW3SIcqsbQX_fC-lVUHYc0JIjnDfd5fvcgCXLpNKc5HSHLGG8iFjNM2F0boqm2UeBgTa1DtHEyeY8fFczNuEW9XKKjuf2Dhq9Z6ZHPkVUmePC7x-7Kb4oKZrlHldbVtorEOf2widplLcf_jJsViOi4zZ_udmG-zwt6Efy0KXO7Cml7uw0Ugus2oPxrO_dSUEiRh5Xmoav3zpN3Jb1zJ7vSZxiUHtorEeiWRREZxNQoM_yJ5J96PIPlz499O7gHYbSNorUiW_B7IPoIexvj4EIhjTSg8zVzoWT3NHZkxZ6cj2NBOaueoIBqtWOl49fA6bwTQKk_Bx8nQCW4j9o0aA7A2gV5ef-hTxtU7PGiN-Ax-GgZ4
openUrl ctx_ver=Z39.88-2004&ctx_enc=info%3Aofi%2Fenc%3AUTF-8&rfr_id=info%3Asid%2Fsummon.serialssolutions.com&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Understanding+the+One-Pixel+Attack%3A+Propagation+Maps+and+Locality+Analysis&rft.jtitle=arXiv.org&rft.au=Danilo+Vasconcellos+Vargas&rft.au=Su%2C+Jiawei&rft.date=2019-02-08&rft.pub=Cornell+University+Library%2C+arXiv.org&rft.eissn=2331-8422