Adversarial perturbation of all the image pixels is computationally intensive and may not be realized in practice. In contrast, an adversarial patch attack where an adversary can choose to perturb a specific subset of pixels in an image, is more practical in fooling a trained image classifier or hiding a person from an object-detection model. […]
Read More