Understanding of Adversarial Attack
Understanding of Adversarial Attack Why we should care adversarial examples? Why they are surprising?
Adversarial example and feature visualization are related intrinsically. Basic algorithm underlying both is to generate image that activate a unit most. For Adversarial attack, the point is to change the image in an in-perceptible way but change the network output dramatically. On the other hand the feature visualization is to generate a perceptually meaningful pattern that represent a natural image that the unit like.
Jan 7, 2020