← Search

Philipp Benz

9 accepted papers

2023

Noisy adversarial representation learning for effective and efficient image obfuscation

UAI 2023poster

Recent real-world applications of deep learning have led to the development of machine learning as a service (MLaaS). However, the scenario of client-server inference presents privacy concerns, where the server processes raw data sent from the user’s client device. One solution to this issue is to p…

2022

Investigating Top-k White-Box and Transferable Black-Box Attack

CVPR 2022poster

Existing works have identified the limitation of top-1 attack success rate (ASR) as a metric to evaluate the attack strength but exclusively investigated it in the white-box setting, while our work extends it to a more practical black-box setting: transferable attack. It is widely reported that stro…

Cited by 51PDFcodeScholar
2021

A Survey on Universal Adversarial Attack

IJCAI 2021poster

The intriguing phenomenon of adversarial examples has attracted significant attention in machine learning and what might be more surprising to the community is the existence of universal adversarial perturbations (UAPs), i.e. a single perturbation to fool the target DNN for most images. With the foc…

Cited by 111SourcePDFScholar
2021

Batch Normalization Increases Adversarial Vulnerability and Decreases Adversarial Transferability: A Non-Robust Feature Perspective

ICCV 2021poster

Batch normalization (BN) has been widely used in modern deep neural networks (DNNs) due to improved convergence. BN is observed to increase the model accuracy while at the cost of adversarial robustness. There is an increasing interest in the ML community to understand the impact of BN on DNNs, espe…

Cited by 49PDFcodeScholar
2021

Universal Adversarial Perturbations Through the Lens of Deep Steganography: Towards a Fourier Perspective

AAAI 2021technical

The booming interest in adversarial attacks stems from a misalignment between human vision and a deep neural network (DNN), ie~a human imperceptible perturbation fools the DNN. Moreover, a single perturbation, often called universal adversarial perturbation (UAP), can be generated to fool the DNN fo…

Cited by 60SourcePDFScholar
2020

UDH: Universal Deep Hiding for Steganography, Watermarking, and Light Field Messaging

NeurIPS 2020poster

Neural networks have been shown effective in deep steganography for hiding a full image in another. However, the reason for its success remains not fully clear. Under the existing cover ($C$) dependent deep hiding (DDH) pipeline, it is challenging to analyze how the secret ($S$) image is encoded sin…

2020

Understanding Adversarial Examples From the Mutual Influence of Images and Perturbations

CVPR 2020poster

A wide variety of works have explored the reason for the existence of adversarial examples, but there is no consensus on the explanation. We propose to treat the DNN logits as a vector for feature representation, and exploit them to analyze the mutual influence of two independent inputs based on the…

Cited by 166PDFScholar
2019

Fast Perception, Planning, and Execution for a Robotic Butler: Wheeled Humanoid M-Hubo

IROS 2019poster

As the aging population grows at a rapid rate, there is an ever growing need for service robot platforms that can provide daily assistance at practical speed with reliable performance. In order to assist with daily tasks such as fetching a beverage, a service robot must be able to perceive its envir…

Cited by 17SourceScholar