DeepRobust- Pytorch Library for adversarial attack and defense in deep learning
github.com
github.com
The language of attacks and defenses implies that we are approaching the kind of robustness that we expect from say a bank app, when in fact we are lightyears away from that.
Sure, you can break systems. That doesn't mean that they aren't useful! In many cases a system will see the same boring input many times over. People are often willing to be a bit flexible and help out when it happens to misread something. The fact that you can intentionally break systems like that, and that you can break them in a particular direction, like making them always think there's no danger in an image, is really worrisome.
Our work shows that your autonomous car won't always work well; that its vision system has some systematic error which we can characterize now. Adversarial attacks show that someone can intentionally make your car see a lane, whenever and wherever they feel like it, and drive you off the road. It's a whole different ballgame, and the language of attack and defense really fits well.
Both non-adversarial non-attack and adversarial attack reflect the vulnerability of the current deep learning models. Thus it is of great significance to study these problem and find countermeasures against those attacks.