2017
Lower bounds on the robustness to adversarial perturbations
NeurIPS 2017poster
The input-output mappings learned by state-of-the-art neural networks are significantly discontinuous. It is possible to cause a neural network used for image recognition to misclassify its input by applying very specific, hardly perceptible perturbations to the input, called adversarial perturbatio…