Understanding the One-Pixel Attack: Propagation Maps and Locality Analysis
Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we propose Propagation Maps which show the influence of the perturbation in each layer of the network. Propagation Maps reveal that even in extre...
Saved in:
Published in | arXiv.org |
---|---|
Main Authors | , |
Format | Paper |
Language | English |
Published |
Ithaca
Cornell University Library, arXiv.org
08.02.2019
|
Subjects | |
Online Access | Get full text |
Cover
Loading…
Abstract | Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we propose Propagation Maps which show the influence of the perturbation in each layer of the network. Propagation Maps reveal that even in extremely deep networks such as Resnet, modification in one pixel easily propagates until the last layer. In fact, this initial local perturbation is also shown to spread becoming a global one and reaching absolute difference values that are close to the maximum value of the original feature maps in a given layer. Moreover, we do a locality analysis in which we demonstrate that nearby pixels of the perturbed one in the one-pixel attack tend to share the same vulnerability, revealing that the main vulnerability lies in neither neurons nor pixels but receptive fields. Hopefully, the analysis conducted in this work together with a new technique called propagation maps shall shed light into the inner workings of other adversarial samples and be the basis of new defense systems to come. |
---|---|
AbstractList | Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we propose Propagation Maps which show the influence of the perturbation in each layer of the network. Propagation Maps reveal that even in extremely deep networks such as Resnet, modification in one pixel easily propagates until the last layer. In fact, this initial local perturbation is also shown to spread becoming a global one and reaching absolute difference values that are close to the maximum value of the original feature maps in a given layer. Moreover, we do a locality analysis in which we demonstrate that nearby pixels of the perturbed one in the one-pixel attack tend to share the same vulnerability, revealing that the main vulnerability lies in neither neurons nor pixels but receptive fields. Hopefully, the analysis conducted in this work together with a new technique called propagation maps shall shed light into the inner workings of other adversarial samples and be the basis of new defense systems to come. |
Author | Danilo Vasconcellos Vargas Su, Jiawei |
Author_xml | – sequence: 1 fullname: Danilo Vasconcellos Vargas – sequence: 2 givenname: Jiawei surname: Su fullname: Su, Jiawei |
BookMark | eNqNysEKgjAYAOARBVn5DoPOgv7TlG4SRUSRhzrL0GWzsdn-Cfn2eegBOn2Xb0Gm2mgxIR4wFgVZDDAnPmIbhiFsUkgS5pHTXdfCouO6lrqh7inoVYugkB-haO4cr15bWljT8YY7aTS98A7puOnZVFxJN9BcczWgxBWZPbhC4f9ckvVhf9sdg86ady_Qla3p7ZixhCjN4oQBhOy_9QX3Yj4Y |
ContentType | Paper |
Copyright | 2019. This work is published under http://arxiv.org/licenses/nonexclusive-distrib/1.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License. |
Copyright_xml | – notice: 2019. This work is published under http://arxiv.org/licenses/nonexclusive-distrib/1.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License. |
DBID | 8FE 8FG ABJCF ABUWG AFKRA AZQEC BENPR BGLVJ CCPQU DWQXO HCIFZ L6V M7S PIMPY PQEST PQQKQ PQUKI PRINS PTHSS |
DatabaseName | ProQuest SciTech Collection ProQuest Technology Collection Materials Science & Engineering Collection ProQuest Central (Alumni) ProQuest Central ProQuest Central Essentials ProQuest Central Technology Collection ProQuest One Community College ProQuest Central SciTech Premium Collection ProQuest Engineering Collection Engineering Database Publicly Available Content Database ProQuest One Academic Eastern Edition (DO NOT USE) ProQuest One Academic ProQuest One Academic UKI Edition ProQuest Central China Engineering Collection |
DatabaseTitle | Publicly Available Content Database Engineering Database Technology Collection ProQuest Central Essentials ProQuest One Academic Eastern Edition ProQuest Central (Alumni Edition) SciTech Premium Collection ProQuest One Community College ProQuest Technology Collection ProQuest SciTech Collection ProQuest Central China ProQuest Central ProQuest Engineering Collection ProQuest One Academic UKI Edition ProQuest Central Korea Materials Science & Engineering Collection ProQuest One Academic Engineering Collection |
DatabaseTitleList | Publicly Available Content Database |
Database_xml | – sequence: 1 dbid: 8FG name: ProQuest Technology Collection url: https://search.proquest.com/technologycollection1 sourceTypes: Aggregation Database |
DeliveryMethod | fulltext_linktorsrc |
Discipline | Physics |
EISSN | 2331-8422 |
Genre | Working Paper/Pre-Print |
GroupedDBID | 8FE 8FG ABJCF ABUWG AFKRA ALMA_UNASSIGNED_HOLDINGS AZQEC BENPR BGLVJ CCPQU DWQXO FRJ HCIFZ L6V M7S M~E PIMPY PQEST PQQKQ PQUKI PRINS PTHSS |
ID | FETCH-proquest_journals_21784532203 |
IEDL.DBID | BENPR |
IngestDate | Tue Sep 24 19:57:20 EDT 2024 |
IsOpenAccess | true |
IsPeerReviewed | false |
IsScholarly | false |
Language | English |
LinkModel | DirectLink |
MergedId | FETCHMERGED-proquest_journals_21784532203 |
OpenAccessLink | https://www.proquest.com/docview/2178453220/abstract/?pq-origsite=%requestingapplication% |
PQID | 2178453220 |
PQPubID | 2050157 |
ParticipantIDs | proquest_journals_2178453220 |
PublicationCentury | 2000 |
PublicationDate | 20190208 |
PublicationDateYYYYMMDD | 2019-02-08 |
PublicationDate_xml | – month: 02 year: 2019 text: 20190208 day: 08 |
PublicationDecade | 2010 |
PublicationPlace | Ithaca |
PublicationPlace_xml | – name: Ithaca |
PublicationTitle | arXiv.org |
PublicationYear | 2019 |
Publisher | Cornell University Library, arXiv.org |
Publisher_xml | – name: Cornell University Library, arXiv.org |
SSID | ssj0002672553 |
Score | 3.182967 |
SecondaryResourceType | preprint |
Snippet | Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we... |
SourceID | proquest |
SourceType | Aggregation Database |
SubjectTerms | Feature maps Neural networks Pixels Propagation |
Title | Understanding the One-Pixel Attack: Propagation Maps and Locality Analysis |
URI | https://www.proquest.com/docview/2178453220/abstract/ |
hasFullText | 1 |
inHoldings | 1 |
isFullTextHit | |
isPrint | |
link | http://utb.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwfV1bS8MwFD5sK4JvXvEyR0BfQ9N754uodJZhZxEHextJmopMZm0r-ORv96S0Kgh7DAkhCYfznct3cgAuAsYz5XqC5og11LUYoyL3NNc1c5gM0SFQut45mfnx3J0uvEUP4q4WRtMqO53YKOrsTeoYuYmmc-h6KH7M5EJHAWRtXhXvVPeP0nnWtplGHwzbcnXC1riJZunjT7zF9gO0np1_KrfBkckOGCkvVLkLPbXeg62GfimrfZjO_9aYEDTKyMNa0fTlU72S67rmcnVJ0hId3OfmJUnCi4rganKvsQgtadL9LnIA55Po6Tam3QGWrbhUy9_LOYcwQL9fHQHxGFOZsmTAfdsVuc8ly2wxdkLFPMWC7BiGm3Y62Tx9CtuI_eOGgBwOYVCXH-oM8bUWI-iHk7tR-4A4Sr6ib6E3heg |
link.rule.ids | 786,790,12792,21416,33408,33779,43635,43840 |
linkProvider | ProQuest |
linkToHtml | http://utb.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwfV3fS8MwED50Q_TNn_hjakBfg1mbtJ0vImKts5192GBvJW3SIcqsbQX_fC-lVUHYc0JIjnDfd5fvcgCXLpNKc5HSHLGG8iFjNM2F0boqm2UeBgTa1DtHEyeY8fFczNuEW9XKKjuf2Dhq9Z6ZHPkVUmePC7x-7Kb4oKZrlHldbVtorEOf2widplLcf_jJsViOi4zZ_udmG-zwt6Efy0KXO7Cml7uw0Ugus2oPxrO_dSUEiRh5Xmoav3zpN3Jb1zJ7vSZxiUHtorEeiWRREZxNQoM_yJ5J96PIPlz499O7gHYbSNorUiW_B7IPoIexvj4EIhjTSg8zVzoWT3NHZkxZ6cj2NBOaueoIBqtWOl49fA6bwTQKk_Bx8nQCW4j9o0aA7A2gV5ef-hTxtU7PGiN-Ax-GgZ4 |
openUrl | ctx_ver=Z39.88-2004&ctx_enc=info%3Aofi%2Fenc%3AUTF-8&rfr_id=info%3Asid%2Fsummon.serialssolutions.com&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Understanding+the+One-Pixel+Attack%3A+Propagation+Maps+and+Locality+Analysis&rft.jtitle=arXiv.org&rft.au=Danilo+Vasconcellos+Vargas&rft.au=Su%2C+Jiawei&rft.date=2019-02-08&rft.pub=Cornell+University+Library%2C+arXiv.org&rft.eissn=2331-8422 |