Skip to main content
Fig. 2 | EURASIP Journal on Information Security

Fig. 2

From: Deep neural rejection against adversarial examples

Fig. 2

Our defense-aware attack against an RBF SVM with rejection, on a 3-class bi-dimensional classification problem. The initial sample x0 and the adversarial example x are respectively represented as a red hexagon and a green star, while the 2-norm perturbation constraint x0x2ε is shown as a black circle. The left plot shows the decision region of each class, along with the reject region (in white). The right plot shows the values of the attack objective Ω(x) (in colors), which correctly enforces our attacks to avoid the reject region

Back to article page