Adversarial Robustness
摘要
Szegedy et al. (2014) discovered that neural networks are vulnerable to adversarial examples, which are true examples perturbed with small artificial noise to fake the classifiers. Since that finding was reported, many methods have been proposed to study attacks on neural network using adversarial examples and defences against such adversarial attacks. This chapter discusses the theory of adversarial robustness and its relation to generalizability and privacy preservation.