Computer Vision News - October 2020

Research 10 Figure 8: attention maps of the network on normal images compared to adversarial On the right, the plot shows the 2D embeddings of the deep features using t-SNE, where we can see that adversarial features are almost linearly separable (after some non-linear transformations) from normal features. This doesn’t happen with natural images, as further discussed below. Figure 7: results of detection of adversarial attacks The table on the left of the image below reports the results of state-of-the-art detectors on the chosen adversarial attacks. This demonstrates very robust performance against these attacks , especially from the KD-based detectors.

RkJQdWJsaXNoZXIy NTc3NzU=