Overview
Syllabus
Introduction
3D adversarial objects
Physical attacks on traffic signs
Adversarial Patches to Attack Person Detection
Semantic Segmentation and Object Detection
LIDAR attack
Definitions
Problem Formulation
Fast Gradient Sign Method • Goodfellow et al. proposed the Fast Gradient Sign Method FGSM
Basic Iterative Method
Carlini-Wagner Attack
Problems and Challenges
Other Problems
Contributions
Trust Region Optimization
Updating the Trust Region
Trust region example - Initial Start
Iteration 1
Final Trajectory after 20 iterations
Proposed Method
Metrics
Types of attacks used
Summary of setup
Time Performance on ImageNet
Qualitative Results
ImageNet Results
Second order attack results
Conclusion
Taught by
UCF CRCV