Berat Tuna Karlı, Attack Independent Perceptual Improvement of Adversarial Examples
This research aims to enhance the perceptual quality of adversarial attacks, regardless of the type of attack used. To achieve this, the study proposes an integration of two seperate attack independent techniques. The first technique, called Normalized Variance Weighting, applies a variance map to intensify the perturbations in high variance areas. The second technique, called the Minimization Method, minimizes the perceptual distance between the benign and adversarial example iteratively. Integrated Method, with the first method applied during the attack and the second method applied after the attack has quantifically the best visual quality.
Date: 23.12.2022 / 10:00 Place: A108









