A

Adversarial Examples on Object Recognition

ACM Computing Surveys, vol. 53, pp. 1–38

Abstract

Deep neural networks are at the forefront of machine learning research. However, despite achieving impressive performance on complex tasks, they can be very sensitive: Small perturbations of inputs can be sufficient to induce incorrect behavior. Such perturbations, called adversarial examples, are intentionally designed to test the network’s sensitivity to distribution drifts. Given their surprisingly small size, a wide body of literature conjectures on their existence and how this phenomenon can be mitigated. In this article, we discuss the impact of adversarial examples on security, safety, and robustness of neural networks. We start by introducing the hypotheses behind their existence, the methods used to construct or protect against them, and the capacity to transfer adversarial examples between different machine learning models. Altogether, the goal is to provide a comprehensive and self-contained survey of this growing field of research.

Authors 3

  1. Radboud University Nijmegen

    Affiliation as printed

    Radboud University, Toernooiveld, Nijmegen, EC, The Netherlands

  2. Radboud University Nijmegen

    Affiliation as printed

    Radboud University, Toernooiveld, Nijmegen, EC, The Netherlands

  3. Joost Visser Aachen

    Leiden University

    Affiliation as printed

    Leiden University, Leiden, The Netherlands

Cited by 137 stored of 139

No patents citing this paper on Lens.org (checked 2026-10-11).

References 135