Advbox: a toolbox to generate adversarial examples that fool neural networks
Dou Goodman Hao Xin Wang Yang Xiong Junfeng、Zhang HuanBaidu X-LabBeijing, China{wangyang62,
Abstract
In recent years, neural networks have been extensively deployed for computer vision tasks, particularly visual classification problems, where new algorithms reported to achieve or even surpass the human performance. Recent studies have shown that they are all vulnerable to the attack of adversarial examples. Small and often imperceptible perturbations to the input images are sufficient to fool the most powerful neural networks. Advbox is a toolbox suite to not only generate adversarial examples that fool neural networks in PaddlePaddle, PyTorch, Caffe2, MxNet, Keras, TensorFlow, but also benchmarks the robustness of machine learning models. Compared to previous work, our platform supports black box attacks on Machine-Learning-as-a-service, as well as more attack scenarios, such as Face Recognition Attack, Stealth T-shirt, and DeepFake Face Detect. AdvBox is openly available at https://github.com/advboxes/AdvBox. It now supports Python 3.
原文 arXiv:2001.05574;中英对照 + 大白话阅读 https://aha.fim.ai/paper/2001.05574v5