%PDF-1.3 1 0 obj << /Kids [ 3 0 R 4 0 R 5 0 R 6 0 R 7 0 R 8 0 R 9 0 R 10 0 R 11 0 R ] /Type /Pages /Count 9 >> endobj 2 0 obj << /Title (Art of Singular Vectors and Universal Adversarial Perturbations) /Producer (PyPDF2) /Author (Valentin Khrulkov\054 Ivan Oseledets) /Subject (2018 IEEE Conference on Computer Vision and Pattern Recognition) >> endobj 3 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 13 0 R /Resources << /XObject << /x8 14 0 R /x6 17 0 R /x12 20 0 R /x10 23 0 R >> /ExtGState << /s9 26 0 R /s11 29 0 R /a0 << /CA 1 /ca 1 >> /R23 32 0 R /s5 33 0 R /s7 36 0 R >> /Font << /F2 39 0 R /R28 40 0 R /F1 43 0 R /R38 44 0 R /R36 47 0 R /R34 52 0 R /R32 57 0 R /R24 60 0 R /R30 64 0 R /R26 68 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 72 0 R 73 0 R 74 0 R 75 0 R 76 0 R 77 0 R 78 0 R 79 0 R 80 0 R 81 0 R 82 0 R 83 0 R 84 0 R 85 0 R 86 0 R ] >> endobj 4 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 87 0 R /Resources << /ExtGState << /R23 32 0 R >> /Font << /R59 88 0 R /R55 91 0 R /R57 96 0 R /F2 101 0 R /F1 102 0 R /R61 103 0 R /R63 108 0 R /R38 44 0 R /R36 47 0 R /R34 52 0 R /R32 57 0 R /R24 60 0 R /R30 64 0 R /R26 68 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 111 0 R 112 0 R 113 0 R 114 0 R 115 0 R 116 0 R 117 0 R 118 0 R 119 0 R 120 0 R ] >> endobj 5 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 121 0 R /Resources << /ExtGState << /R23 32 0 R >> /Font << /F2 122 0 R /R59 88 0 R /R55 91 0 R /R57 96 0 R /R32 57 0 R /F1 123 0 R /R30 64 0 R /R63 108 0 R /R38 44 0 R /R36 47 0 R /R34 52 0 R /R87 124 0 R /R24 60 0 R /R85 127 0 R /R26 68 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 130 0 R 131 0 R 132 0 R 133 0 R 134 0 R 135 0 R 136 0 R 137 0 R 138 0 R 139 0 R 140 0 R 141 0 R 142 0 R 143 0 R 144 0 R ] >> endobj 6 0 obj << /Parent 1 0 R /Rotate 0 /Contents 145 0 R /Resources << /XObject << /R361 146 0 R /R360 149 0 R /R363 150 0 R /R362 151 0 R /R365 152 0 R /R364 153 0 R /R366 154 0 R /R137 155 0 R /R138 156 0 R /R248 157 0 R /R249 158 0 R /R246 159 0 R /R247 160 0 R /R244 161 0 R /R245 162 0 R /R242 163 0 R /R243 164 0 R /R240 165 0 R /R241 166 0 R /R163 167 0 R /R162 168 0 R /R161 169 0 R /R160 170 0 R /R167 171 0 R /R166 172 0 R /R165 173 0 R /R164 174 0 R /R169 175 0 R /R168 176 0 R /R371 177 0 R /R279 270 0 R /R278 271 0 R /R273 272 0 R /R272 273 0 R /R271 274 0 R /R270 275 0 R /R277 276 0 R /R276 277 0 R /R275 278 0 R /R274 279 0 R /R178 280 0 R /R179 281 0 R /R159 282 0 R /R174 283 0 R /R175 284 0 R /R176 285 0 R /R177 286 0 R /R170 287 0 R /R171 288 0 R /R172 289 0 R /R173 290 0 R /R181 291 0 R /R265 292 0 R /R266 293 0 R /R267 294 0 R /R260 295 0 R /R261 296 0 R /R349 200 0 R /R348 201 0 R /R347 202 0 R /R346 203 0 R /R345 204 0 R /R344 205 0 R /R343 206 0 R /R342 207 0 R /R341 208 0 R /R340 209 0 R /R191 297 0 R /R196 298 0 R /R184 299 0 R /R197 300 0 R /R194 301 0 R /R195 302 0 R /R219 303 0 R /R129 304 0 R /R218 305 0 R /R322 183 0 R /R198 306 0 R /R358 220 0 R /R359 221 0 R /R213 307 0 R /R212 308 0 R /R215 309 0 R /R214 310 0 R /R217 311 0 R /R216 312 0 R /R350 228 0 R /R351 229 0 R /R352 230 0 R /R353 231 0 R /R354 232 0 R /R355 235 0 R /R356 234 0 R /R357 236 0 R /R299 237 0 R /R298 238 0 R /R118 313 0 R /R136 314 0 R /R291 239 0 R /R290 240 0 R /R293 241 0 R /R292 242 0 R /R295 243 0 R /R294 244 0 R /R297 245 0 R /R115 315 0 R /R186 316 0 R /R202 317 0 R /R264 318 0 R /R200 319 0 R /R201 320 0 R /R206 321 0 R /R207 365 0 R /R204 323 0 R /R180 336 0 R /R208 366 0 R /R183 337 0 R /R127 324 0 R /R126 325 0 R /R124 326 0 R /R329 179 0 R /R122 327 0 R /R121 328 0 R /R321 180 0 R /R320 181 0 R /R323 182 0 R /R128 329 0 R /R288 184 0 R /R289 185 0 R /R187 339 0 R /R282 367 0 R /R283 368 0 R /R280 369 0 R /R263 370 0 R /R286 186 0 R /R284 371 0 R /R285 187 0 R /R189 340 0 R /R188 341 0 R /R239 373 0 R /R238 374 0 R /R237 375 0 R /R268 376 0 R /R235 377 0 R /R234 378 0 R /R233 379 0 R /R232 380 0 R /R231 381 0 R /R230 382 0 R /R130 330 0 R /R131 331 0 R /R132 332 0 R /R133 333 0 R /R134 334 0 R /R135 335 0 R /R338 188 0 R /R339 189 0 R /R336 190 0 R /R337 191 0 R /R334 192 0 R /R335 193 0 R /R332 194 0 R /R333 195 0 R /R330 196 0 R /R331 197 0 R /R182 338 0 R /R113 357 0 R /R203 322 0 R /R228 383 0 R /R229 384 0 R /R281 372 0 R /R220 386 0 R /R221 387 0 R /R222 388 0 R /R223 389 0 R /R224 390 0 R /R225 391 0 R /R226 392 0 R /R227 393 0 R /R309 210 0 R /R308 211 0 R /R303 212 0 R /R302 213 0 R /R301 214 0 R /R296 246 0 R /R307 216 0 R /R306 217 0 R /R305 218 0 R /R304 219 0 R /R147 342 0 R /R300 215 0 R /R149 343 0 R /R148 344 0 R /R236 394 0 R /R192 345 0 R /R314 199 0 R /R315 178 0 R /R316 222 0 R /R317 223 0 R /R310 224 0 R /R311 225 0 R /R312 226 0 R /R313 227 0 R /R199 348 0 R /R318 198 0 R /R319 233 0 R /R262 385 0 R /R259 397 0 R /R258 398 0 R /R255 399 0 R /R254 400 0 R /R257 401 0 R /R256 402 0 R /R251 403 0 R /R250 404 0 R /R253 405 0 R /R252 406 0 R /R156 349 0 R /R157 350 0 R /R154 351 0 R /R155 352 0 R /R152 353 0 R /R153 354 0 R /R150 355 0 R /R151 356 0 R /R269 407 0 R /R193 346 0 R /R158 358 0 R /R210 396 0 R /R211 395 0 R /R190 347 0 R >> /ExtGState << /R112 147 0 R /R23 32 0 R >> /Font << /R59 88 0 R /R209 408 0 R /R287 247 0 R /R117 359 0 R /F2 410 0 R /R28 40 0 R /F1 411 0 R /R36 47 0 R /R34 52 0 R /R32 57 0 R /R24 60 0 R /R30 64 0 R /R26 68 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /Group 269 0 R /MediaBox [ 0 0 612 792 ] /Annots [ 412 0 R 413 0 R 414 0 R 415 0 R 416 0 R 417 0 R 418 0 R 419 0 R 420 0 R 421 0 R 422 0 R 423 0 R 424 0 R 425 0 R 426 0 R ] /Type /Page >> endobj 7 0 obj << /Parent 1 0 R /Rotate 0 /Contents 427 0 R /Resources << /XObject << /R416 428 0 R /R405 442 0 R /R398 449 0 R /R399 450 0 R /R400 451 0 R >> /ExtGState << /R112 147 0 R /R23 32 0 R >> /Font << /R57 96 0 R /F2 452 0 R /R406 453 0 R /F1 456 0 R /R401 433 0 R /R403 443 0 R /R408 457 0 R /R394 429 0 R /R412 461 0 R /R396 446 0 R /R410 465 0 R /R392 436 0 R /R414 439 0 R /R36 47 0 R /R34 52 0 R /R32 57 0 R /R24 60 0 R /R30 64 0 R /R26 68 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /Group 269 0 R /MediaBox [ 0 0 612 792 ] /Annots [ 469 0 R 470 0 R 471 0 R 472 0 R 473 0 R 474 0 R 475 0 R 476 0 R 477 0 R 478 0 R 479 0 R 480 0 R 481 0 R 482 0 R ] /Type /Page >> endobj 8 0 obj << /Parent 1 0 R /Rotate 0 /Contents 483 0 R /Resources << /XObject << /R428 484 0 R >> /ExtGState << /R112 147 0 R /R23 32 0 R >> /Font << /R394 429 0 R /R55 91 0 R /R396 446 0 R /R57 96 0 R /R392 436 0 R /F2 485 0 R /R28 40 0 R /F1 486 0 R /R38 44 0 R /R36 47 0 R /R34 52 0 R /R32 57 0 R /R24 60 0 R /R30 64 0 R /R26 68 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /Group 269 0 R /MediaBox [ 0 0 612 792 ] /Annots [ 487 0 R 488 0 R 489 0 R 490 0 R 491 0 R 492 0 R ] /Type /Page >> endobj 9 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 493 0 R /Resources << /XObject << /R448 494 0 R /R441 495 0 R /R442 496 0 R /R443 497 0 R /R444 498 0 R /R445 499 0 R /R446 500 0 R /R447 501 0 R >> /ExtGState << /R23 32 0 R >> /Font << /F2 502 0 R /R28 40 0 R /F1 503 0 R /R36 47 0 R /R34 52 0 R /R32 57 0 R /R24 60 0 R /R30 64 0 R /R26 68 0 R >> /ProcSet [ /Text /ImageC /ImageB /PDF /ImageI ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 504 0 R 505 0 R 506 0 R 507 0 R 508 0 R 509 0 R ] >> endobj 10 0 obj << /Parent 1 0 R /Rotate 0 /Contents 510 0 R /Resources << /XObject << /R468 511 0 R /R469 512 0 R >> /ExtGState << /R112 147 0 R /R23 32 0 R >> /Font << /R394 429 0 R /R396 446 0 R /R392 436 0 R /F2 513 0 R /R28 40 0 R /F1 514 0 R /R401 433 0 R /R38 44 0 R /R36 47 0 R /R34 52 0 R /R32 57 0 R /R24 60 0 R /R30 64 0 R /R26 68 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /Group 269 0 R /MediaBox [ 0 0 612 792 ] /Annots [ 515 0 R 516 0 R 517 0 R 518 0 R 519 0 R 520 0 R 521 0 R 522 0 R 523 0 R 524 0 R 525 0 R 526 0 R 527 0 R 528 0 R ] /Type /Page >> endobj 11 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 529 0 R /Resources << /ExtGState << /R23 32 0 R >> /Font << /F2 530 0 R /F1 531 0 R /R24 60 0 R /R30 64 0 R /R26 68 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 532 0 R 533 0 R 534 0 R 535 0 R 536 0 R 537 0 R 538 0 R 539 0 R 540 0 R 541 0 R 542 0 R 543 0 R 544 0 R 545 0 R 546 0 R 547 0 R 548 0 R 549 0 R 550 0 R 551 0 R 552 0 R 553 0 R 554 0 R 555 0 R 556 0 R 557 0 R 558 0 R 559 0 R 560 0 R 561 0 R 562 0 R ] >> endobj 12 0 obj << /Type /Catalog /Pages 1 0 R >> endobj 13 0 obj << /Length 19984 >> stream q q q 0.1 0 0 0.1 0 0 cm /R23 gs 0 g q 10 0 0 10 0 0 cm BT /R24 14.3462 Tf 1 0 0 1 104.83 675.067 Tm [ (Art) -249.993 (of) -250.012 (singular) -249.993 (v) 9.99625 (ectors) -249.988 (and) -249.991 (uni) 10.0065 (v) 9.99625 (ersal) -249.998 (adv) 9.99455 (ersarial) -250.012 (perturbations) ] TJ /R26 11.9552 Tf 25.9031 -37.8582 Td [ (V) 110.995 (alentin) -250 (Khrulk) 9.99418 (o) 14.9851 (v) ] TJ -65.8121 -13.9469 Td [ (Sk) 10.0049 (olk) 9.98499 (o) 14.9862 (v) 19.9853 (o) -250 (Institute) -250.015 (of) -250.015 (Science) -250.006 (and) -249.987 (T) 70.0164 (echnology) ] TJ /R28 8.9664 Tf 21.225 -13.948 Td (valentin\056khrulkov\100skolkovotech\056ru) Tj /R26 11.9552 Tf 298.957 27.8949 Td [ (Iv) 25.0038 (an) -250.008 (Oseledets) ] TJ -74.7852 -13.9469 Td [ (Sk) 10.0044 (olk) 9.98397 (o) 14.9851 (v) 19.9843 (o) -250.002 (Institute) -250.016 (of) -250.014 (Science) -250.006 (and) -249.985 (T) 70.0164 (echnology) ] TJ 11.7039 -13.948 Td [ (Institute) -250.016 (of) -250.014 (Numerical) -249.989 (Mathematics) -249.989 (RAS) ] TJ /R28 8.9664 Tf 36.4211 -13.948 Td (i\056oseledets\100skoltech\056ru) Tj /R24 11.9552 Tf -212.448 -41.0461 Td (Abstract) Tj /R30 9.9626 Tf -83.9277 -23.9258 Td [ (V) 73.9913 (ulner) 14.9969 (ability) -382.02 (of) -382.002 (Deep) -382.016 (Neur) 14.9975 (al) -382.002 (Networks) -382.012 (\050DNNs\051) -381.985 (to) -382.002 (ad\055) ] TJ -11.9551 -11.9551 Td [ (ver) 9.99588 (sarial) -380.017 (attac) 20.0163 (ks) -380.994 (has) -381.019 (been) -380.014 (attr) 15.0036 (acting) -381.01 (a) -380.01 (lot) -381.015 (of) -380.003 (attention) -380.99 (in) ] TJ 11.9551 TL T* [ (r) 37.0196 (ecent) -265.015 (studies\056) -353.985 (It) -265.011 (has) -264.018 (been) -265.013 (shown) -265.02 (that) -264.99 (for) -264.017 (many) -265.007 (state) -264.993 (of) -265.002 (the) ] TJ 11.9559 TL T* [ (art) -350.982 (DNNs) -351.004 (performing) -350.994 (ima) 10.013 (g) 10.0032 (e) -351.005 <636c6173736902636174696f6e> -350.983 (ther) 36.9889 (e) -351.985 (e) 19.9918 (xist) -350.983 (uni\055) ] TJ 11.9551 TL T* [ (ver) 9.99588 (sal) -278.994 (adver) 10.0057 (sarial) -279.015 (perturbations) -278.987 (\227) -279.981 (ima) 10.013 (g) 10.0032 (e\055a) 9.99588 (gnostic) -278.98 (pertur) 19.982 (\055) ] TJ T* [ (bations) -255.015 (mer) 37.0177 (e) -256 (addition) -255.009 (of) -255.984 (whic) 14.9987 (h) -255.011 (to) -255.004 (natur) 15.0073 (al) -255.984 (ima) 10.013 (g) 10.0032 (es) -255.014 (with) -256.004 (high) ] TJ T* [ (pr) 44.9839 (obability) -267.009 (leads) -266.996 (to) -267.002 (their) -266.993 <6d6973636c6173736902636174696f6e2e> -361.001 (In) -267.012 (this) -266.99 (work) -266.995 (we) ] TJ T* [ (pr) 44.9839 (opose) -399.995 (a) -400.007 (ne) 15.0183 (w) -399.018 (algorithm) -400 (for) -399.993 (constructing) -400.002 (suc) 14.9852 (h) -400.007 (univer) 10.013 (sal) ] TJ T* [ (perturbations\056) -306 (Our) -237.006 (appr) 44.9937 (oac) 14.984 (h) -237.995 (is) -237.006 (based) -237.982 (on) -237.99 (computing) -236.983 (the) -237.992 (so\055) ] TJ 11.9563 TL (called) ' /R32 9.9626 Tf 28.1398 0 Td [ (\050) -0.89997 ] TJ /R34 9.9626 Tf 3.87422 0 Td [ (p) -0.09986 (\073) -167.781 (q) -0.40006 ] TJ /R32 9.9626 Tf 14.2457 0 Td [ (\051) -0.89997 ] TJ /R30 9.9626 Tf 3.87422 0 Td [ (\055singular) -380.992 (vector) 10.0032 (s) -380.009 (of) -380.983 (the) -380.008 (J) 35.0089 (acobian) -381.008 (matrices) -379.991 (of) ] TJ -50.134 -11.9547 Td [ (hidden) -228.998 (layer) 10.0081 (s) -229.014 (of) -229.008 (a) -229.996 (net) 0.98758 (work\056) -304.006 (Result) 1.00473 (ing) -229.984 (perturbations) -228.994 (pr) 36.9865 (esent) ] TJ 11.9551 TL T* [ (inter) 36.9951 (esting) -254.99 (visual) -254.991 (patterns\054) -257.016 (and) -255.002 (by) -255.995 (using) -254.987 (only) -255.004 (64) -255.006 (ima) 10.013 (g) 10.0032 (es) -255.994 (we) ] TJ T* [ (wer) 36.9895 (e) -384.019 (able) -384.001 (to) -382.983 (construct) -383.981 (univer) 10.013 (sal) -383.996 (perturbations) -383.987 (with) -383.982 (mor) 36.9889 (e) ] TJ T* [ (than) -322.983 (60) -322.995 (\045) -321.984 (fooling) -323.002 (r) 14.984 (ate) -322.998 (on) -322.995 (the) -322.017 (dataset) -323.013 (consisting) -322.995 (of) -322.993 (50000) ] TJ 11.9559 TL T* [ (ima) 10.0136 (g) 10.0032 (es\056) -309.003 (W) 91.9865 (e) -248.002 (also) -248.014 (in) 40.0056 (vestigate) -248.013 (a) -247.993 (corr) 36.9865 (elation) -248.005 (between) -247.981 (the) -247.99 (max\055) ] TJ 11.9551 TL T* [ (imal) -292.988 (singular) -293.003 (value) -293.001 (of) -292.998 (the) -293.003 (J) 35.0089 (acobian) -292.982 (matrix) -294.005 (and) -292.995 (the) -293.003 (fooling) ] TJ T* [ (r) 14.984 (ate) -223.014 (of) -223.99 (the) -223.014 (corr) 36.9865 (esponding) -222.982 (singular) -223.994 (vector) 111.006 (\054) -229.018 (and) -223.007 (show) -222.992 (that) -224.017 (the) ] TJ T* [ (constructed) -250.003 (perturbations) -250.011 (g) 10.0032 (ener) 15.0196 (alize) -250.016 (acr) 45.0194 (oss) -250.02 (networks\056) ] TJ /R24 11.9552 Tf 35.9133 TL T* [ (1\056) -249.99 (Intr) 18.0146 (oduction) ] TJ /R26 9.9626 Tf 11.9551 -18.9449 Td [ (Deep) -279.013 (Neural) -279.989 (Net) 0.98635 (w) 10 (orks) -280.019 (\050DNNs\051) -279.004 (with) -278.99 (great) -279.012 (success) -279.983 (ha) 19.9967 (v) 14.9828 (e) ] TJ -11.9551 -11.9551 Td [ (been) -216.002 (applied) -217.002 (to) -215.991 (man) 14.9901 (y) -217.018 (practical) -215.997 (problems) -216.991 (in) -215.991 (computer) -217 (vision) ] TJ 11.9547 TL (\133) ' ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 53.4297 248.388 Tm (11) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 63.3922 248.388 Tm (\054) Tj ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 68.0848 248.388 Tm (20) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 78.0473 248.388 Tm (\054) Tj ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 82.7398 248.388 Tm (9) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 87.7211 248.388 Tm [ (\135) -220.986 (and) -219.996 (in) -221.01 (audio) -221.004 (and) -221.016 (te) 14.9803 (xt) -221.01 (processing) -220.995 (\133) ] TJ ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 225.823 248.388 Tm (7) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 230.804 248.388 Tm (\054) Tj ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 235.497 248.388 Tm (13) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 245.459 248.388 Tm (\054) Tj ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 250.142 248.388 Tm (4) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 255.123 248.388 Tm [ (\135\056) -301.009 (Ho) 24.9836 (w\055) ] TJ -205.011 -11.9551 Td [ (e) 25.0111 (v) 14.9828 (er) 39.986 (\054) -503.012 (it) -451.989 (w) 10.0014 (as) -452.001 (disco) 14.9963 (v) 14.9828 (ered) -452.01 (that) -451.988 (man) 14.9901 (y) -453.018 (state\055of\055the\055art) -451.991 (DNNs) ] TJ 11.9551 TL T* [ (are) -347.013 (vulnerable) -348.002 (to) -346.989 (adv) 14.984 (ersarial) -348.019 (attacks) -346.989 (\133) ] TJ ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 203.925 224.478 Tm (6) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 208.906 224.478 Tm (\054) Tj ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 214.864 224.478 Tm (14) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 224.827 224.478 Tm (\054) Tj ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 230.774 224.478 Tm (21) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 240.737 224.478 Tm [ (\135\054) -372.016 (based) -348.013 (on) ] TJ -190.625 -11.9559 Td [ (adding) -347.998 (a) ] TJ /R30 9.9626 Tf 38.475 0 Td (perturbation) Tj /R26 9.9626 Tf 53.8367 0 Td [ (of) -348.019 (a) -347.986 (small) -347.992 (magnitude) -347.984 (to) -348.008 (the) -348.013 (image\056) ] TJ -92.3117 -11.9551 Td [ (Such) -484.017 (perturbations) -483.019 (are) -484.01 (carefully) -483.993 (constructed) -482.993 (in) -483.985 (order) -483.998 (to) ] TJ 11.9551 TL T* [ (lead) -305.004 (to) -304.996 <6d6973636c6173736902636174696f6e> -305.013 (of) -305.007 (the) -305 (perturbed) -304.996 (image) -304.993 (and) -305.003 (more\055) ] TJ T* [ (o) 14.9828 (v) 14.9828 (er) -393.981 (may) -394 (attempt) -395.001 (to) -394 (force) -393.983 (a) -394.018 <73706563690263> -393.993 (predicted) -395.02 (class) -394.003 (\050tar) 19.9942 (\055) ] TJ T* [ (geted) -338.013 (attacks\051\054) -360.006 (as) -337.982 (opposed) -337.995 (to) -338.01 (just) -337.996 (an) 15.0183 (y) -338.017 (class) -338.012 (dif) 24.986 (ferent) -337.985 (from) ] TJ T* [ (the) -267.987 (ground) -268.992 (truth) -268.013 (\050untar) 18.0031 (geted) -269.005 (attacks\051\056) -364.986 (Potential) -269.009 (undesirable) ] TJ 11.9563 TL T* [ (usage) -316.999 (of) -317.004 (adv) 14.9834 (ersarial) -315.985 (perturbations) -317.007 (in) -316.994 (practical) -317.001 (applications) ] TJ 11.9551 TL T* [ (such) -403.019 (as) -402.01 (autonomous) -403.019 (dri) 24.9848 (ving) -401.989 (systems) -402.993 (and) -402.006 (mal) 10.013 (w) 10 (are) -403.004 (detec\055) ] TJ T* [ (tion) -373.992 (has) -372.99 (been) -374.015 (studied) -373.005 (in) -374.004 (\133) ] TJ ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 156.164 116.881 Tm (10) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 166.127 116.881 Tm (\054) Tj ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 172.333 116.881 Tm (8) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 177.314 116.881 Tm [ (\135\056) -680.986 (This) -373.994 (also) -372.982 (moti) 25.0081 (v) 24.9811 (ated) -374.014 (the) ] TJ -127.202 -11.9551 Td [ (research) -288.004 (on) -287.981 (defenses) -289.004 (ag) 5.02 (ainst) -288.01 (v) 24.9811 (arious) -288.014 (kinds) -288 (of) -289.008 (atta) 0.98513 (ck) -289.011 (strate\055) ] TJ 11.9551 TL T* [ (gies) -249.983 (\133) ] TJ ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 71.9699 92.9711 Tm (16) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 81.9324 92.9711 Tm (\054) Tj ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 86.9137 92.9711 Tm (5) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 91.8949 92.9711 Tm (\135\056) Tj -29.8277 -11.9711 Td [ (In) -313.005 (the) -314.018 (recent) -313.01 (w) 10 (ork) -314.019 (Moosa) 20.0199 (vi) ] TJ /R30 9.9626 Tf 115.47 0 Td [ (et) -313.004 (al) ] TJ /R26 9.9626 Tf 18.077 0 Td [ (\056) -313.004 (\133) ] TJ ET Q 0 1 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 204.541 81 Tm (14) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 214.503 81 Tm [ (\135) -313.989 (ha) 19.9967 (v) 14.9828 (e) -313.012 (sho) 24.9934 (wn) -314.019 (that) ] TJ 94.359 473.32 Td [ (there) -450.003 (e) 15.0122 (xist) ] TJ /R30 9.9626 Tf 47.557 0 Td [ (univer) 10.013 (sal) ] TJ /R26 9.9626 Tf 41.477 0 Td [ (adv) 14.9828 (ersarial) -450.003 (perturbations) -450.984 (\227) -449.994 (image\055) ] TJ -89.034 -11.9551 Td [ (agnostic) -262.988 (perturbations) -263.017 (that) -264.02 (cause) -263.015 (most) -262.986 (natural) -263 (images) -262.995 (to) -263.985 (be) ] TJ 11.9563 TL T* [ <6d6973636c617373690265642e> -766.987 (The) 14.9828 (y) -402.006 (were) -401.982 (constructed) -401.987 (by) -402.002 (iterating) -401.987 (o) 14.9828 (v) 14.0026 (e) 1.01454 (r) -402.996 (a) ] TJ 11.9547 TL T* [ (dataset) -292.017 (and) -293.005 (recomputing) -291.99 (the) -293 (\224w) 9.99833 (orst\224) -292.02 (direction) -292.985 (in) -292.02 (the) -293 (space) ] TJ T* [ (of) -222 (images) -221 (by) -221.992 (solving) -220.98 (an) -222.002 (optimization) -221.002 (problem) -222.017 (related) -221.017 (to) -221.992 (ge\055) ] TJ T* [ (ometry) -236.017 (of) -235.997 (the) -235.992 (decision) -236.012 (boundary) 64.9941 (\056) -305.003 (Uni) 24.9909 (v) 14.9828 (ersal) -236 (adv) 14.9828 (ersarial) -236 (per) 19.9918 (\055) ] TJ T* [ (turbations) -289.011 (e) 15.0122 (xhibit) -289.013 (man) 14.9901 (y) -289.006 (interesting) -289.011 (properties) -288.991 (such) -290.02 (as) -289.011 (their) ] TJ T* [ (uni) 24.9934 (v) 14.9828 (ersality) ] TJ /R30 9.9626 Tf 49.4738 0 Td [ (acr) 45.0194 (oss) -284.014 (networks) ] TJ /R26 9.9626 Tf 64.3691 0 Td [ (\054) -293.005 (which) -284.016 (means) -284.016 (that) -284.016 (a) -283.997 (perturba\055) ] TJ -113.843 -11.9563 Td [ (tion) -191.983 (constructed) -191.983 (using) -192.017 (one) -190.983 (DNN) -191.997 (will) -191.983 (perform) -191.997 (relati) 24.986 (v) 14.9828 (ely) -191.997 (well) ] TJ T* [ (for) -250 (other) -249.988 (DNNs\056) ] TJ 11.9551 -11.9547 Td [ (W) 79.9866 (e) -373.001 (present) -372.004 (a) -373.001 (ne) 25.0154 (w) -372.014 (algorithm) -372.997 (for) -372.016 (constructing) -372.997 (uni) 24.9958 (v) 14.9828 (ersal) ] TJ -11.9551 -11.9551 Td [ (perturbations) -388.016 (based) -386.987 (on) -388.004 (solving) -386.994 (simple) -388.019 (optimization) -387.994 (prob\055) ] TJ T* [ (lems) -564.982 (which) -564.009 (correspond) -564.987 (to) -564.994 <026e64696e67> -565.004 (the) -564.014 (so\055called) ] TJ /R32 9.9626 Tf 210.939 0 Td [ (\050) -0.90181 ] TJ /R34 9.9626 Tf 3.87383 0 Td [ (p) -0.10292 (\073) -167.781 (q) -0.40189 ] TJ /R32 9.9626 Tf 14.2449 0 Td [ (\051) -0.90181 ] TJ /R26 9.9626 Tf 3.87422 0 Td (\055) Tj -232.932 -11.9551 Td [ (singular) -278.985 (v) 14.9828 (ector) -279.012 (of) -279.99 (the) -279.005 (Jacobian) -278.998 (matrices) -278.998 (of) -279.012 (feature) -279.997 (ma) 0.99003 (p) -1.01454 (s) -279.007 (of) ] TJ 11.9559 TL T* [ (a) -262 (DNN\056) -261.986 (Our) -261.991 (idea) -261.993 (as) -261.993 (based) -261.986 (on) -261.986 (the) -263.005 (observ) 24.9909 (ation) -262.015 (that) -261.981 (since) -261.986 (the) ] TJ 11.9551 TL T* [ (norm) -395.993 (of) -396.99 (adv) 14.9828 (ersarial) -396.012 (perturbations) -396.993 (is) -395.998 (typically) -396.017 (v) 14.9828 (ery) -396.997 (small\054) ] TJ T* [ (perturbations) -234.983 (in) -235.988 (the) -235.012 (non\055linear) -235.98 (maps) -235 (computed) -236.01 (by) -235.01 (the) -235.99 (DNN) ] TJ T* [ (can) -319.008 (be) -319.006 (reasonably) -318.988 (well) -318.993 (approximated) -319.01 (by) -320.015 (the) -318.996 (Jacobian) -318.991 (ma\055) ] TJ T* [ (trix\056) -467.981 (The) ] TJ /R32 9.9626 Tf 39.4949 0 Td [ (\050) -0.90181 ] TJ /R34 9.9626 Tf 3.875 0 Td [ (p) -0.10047 (\073) -167.781 (q) -0.40189 ] TJ /R32 9.9626 Tf 14.2449 0 Td [ (\051) -0.90181 ] TJ /R26 9.9626 Tf 3.87422 0 Td [ (\055singular) -302.984 (v) 14.9828 (ector) -301.989 (of) -303.008 (a) -301.994 (matrix) ] TJ /R34 9.9626 Tf 113.972 0 Td (A) Tj /R26 9.9626 Tf 10.4859 0 Td [ (is) -302.994 <6465026e6564> -302.008 (as) ] TJ -185.947 -11.9551 Td [ (the) -249.99 (solution) -249.99 (of) -249.995 (the) -249.99 (follo) 24.9983 (wing) -250.017 (optimization) -250.017 (problem) ] TJ /R36 9.9626 Tf 60.0059 -21.668 Td (k) Tj /R34 9.9626 Tf 4.98203 0 Td [ (Av) -0.70086 ] TJ /R36 9.9626 Tf 12.6582 0 Td (k) Tj /R38 6.9738 Tf 4.98203 -1.49414 Td [ (q) -0.60214 ] TJ /R36 9.9626 Tf 7.1668 1.49414 Td (\041) Tj /R32 9.9626 Tf 12.7301 0 Td [ (m) -0.30387 (ax) -0.79889 ] TJ /R34 9.9626 Tf 18.5418 0 Td [ (\073) -0.80379 ] TJ /R36 9.9626 Tf 14.3902 0 Td (k) Tj /R34 9.9626 Tf 4.98086 0 Td [ (v) -0.70086 ] TJ /R36 9.9626 Tf 5.18711 0 Td (k) Tj /R38 6.9738 Tf 4.98086 -1.49414 Td [ (p) -0.90321 ] TJ /R32 9.9626 Tf 7.37305 1.49414 Td [ (\075) -278.787 (1) ] TJ /R34 9.9626 Tf 15.4969 0 Td [ (\073) -0.80379 ] TJ /R26 9.9626 Tf 51.1582 0 Td (\0501\051) Tj -224.634 -21.6668 Td [ (and) -192.982 (if) -192.002 (we) -192.99 (desire) ] TJ /R36 9.9626 Tf 63.5539 0 Td (k) Tj /R34 9.9626 Tf 4.98086 0 Td [ (v) -0.70086 ] TJ /R36 9.9626 Tf 5.18711 0 Td (k) Tj /R38 6.9738 Tf 4.98086 -1.49531 Td [ (p) -0.89971 ] TJ /R32 9.9626 Tf 7.37227 1.49531 Td [ (\075) -0.79889 ] TJ /R34 9.9626 Tf 10.516 0 Td [ (L) -0.60284 ] TJ /R26 9.9626 Tf 8.69883 0 Td [ (instead\054) -203.981 (it) -193.012 (is) -191.992 (suf) 24.986 <026369656e74> -193.002 (to) -191.997 (multiply) ] TJ -105.29 -11.9551 Td [ (the) -219.995 (solution) -221.015 (of) -220 (\050) ] TJ ET Q 1 0 0 rg q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 371.348 271.882 Tm (1) Tj ET Q 0 g q 10 0 0 10 0 0 cm BT /R26 9.9626 Tf 1 0 0 1 376.329 271.882 Tm [ (\051) -220.005 (by) ] TJ /R34 9.9626 Tf 17.6691 0 Td [ (L) -0.60039 ] TJ /R26 9.9626 Tf 6.78008 0 Td [ (\056) -299.987 (Uni) 24.9909 (v) 14.9828 (ersal) -220.003 (adv) 14.9828 (ersarial) -220.983 (perturbations) ] TJ -91.916 -11.9551 Td [ (are) -250.01 (typic) 1 (ally) -249.983 (generated) -249.995 (wi) 0.99003 (th) -249.988 (a) -250.002 (bound) -248.993 (in) -249.988 (the) ] TJ /R36 9.9626 Tf 172.613 0 Td (1) Tj /R26 9.9626 Tf 9.96289 0 Td [ (\055norm\054) -250.017 (which) ] TJ -182.576 -11.9559 Td [ (moti) 25.0081 (v) 24.9811 (ates) -247.013 (the) -247.99 (usage) -247.99 (of) -247.015 (such) -247.988 (general) -247.018 (construction\056) -309.002 (T) 79.9916 (o) -247.993 (obtain) ] TJ 11.9551 TL (the) ' /R32 9.9626 Tf 14.2309 0 Td [ (\050) -0.90181 ] TJ /R34 9.9626 Tf 3.875 0 Td [ (p) -0.10047 (\073) -167.781 (q) -0.40189 ] TJ /R32 9.9626 Tf 14.2449 0 Td [ (\051) -0.90181 ] TJ /R26 9.9626 Tf 3.87422 0 Td [ (\055singular) -206.02 (v) 14.9828 (ectors) -207.019 (we) -206.005 (use) -207.019 (a) -206.01 <6d6f646902636174696f6e> -207.005 (of) -206.005 (the) -207.014 (stan\055) ] TJ -36.225 -11.9551 Td [ (dard) -271.991 (po) 24.986 (wer) -273.018 (method\054) -278 (which) -272.018 (is) -271.979 (adapted) -273.003 (to) -271.984 (arbitrary) ] TJ /R34 9.9626 Tf 200.523 0 Td [ (p) -0.10292 ] TJ /R26 9.9626 Tf 5.01289 0 Td (\055norms\056) Tj -205.536 -11.9551 Td [ (The) -249.993 (main) -250.017 (contrib) 20.0187 (utions) -250.002 (of) -249.997 (our) -249.993 (paper) -249.997 (are) ] TJ /R36 9.9626 Tf 9.96289 -19.725 Td <0f> Tj /R26 9.9626 Tf 9.96211 0 Td [ (W) 79.9866 (e) -301.994 (propose) -302.989 (an) -301.989 (algorithm) -303.008 (for) -301.989 (generating) -302.008 (uni) 24.9958 (v) 14.9828 (ersal) -303.008 (ad\055) ] TJ T* [ (v) 14.9828 (ersarial) -521.991 (perturbation\054) -589.005 (using) -522.001 (the) -521.001 (generalized) -521.986 (po) 24.986 (wer) ] TJ T* [ (method) -194.017 (for) -194.009 (computing) -193.997 (the) ] TJ /R32 9.9626 Tf 104.024 0 Td [ (\050) -0.90181 ] TJ /R34 9.9626 Tf 3.875 0 Td [ (p) -0.10292 (\073) -167.781 (q) -0.40189 ] TJ /R32 9.9626 Tf 14.2449 0 Td [ (\051) -0.90181 ] TJ /R26 9.9626 Tf 3.87422 0 Td [ (\055singular) -193.982 (v) 14.9828 (ectors) -194.002 (of) -194.007 (the) ] TJ -126.018 -11.9563 Td [ (Jacobian) -249.983 (matrices) -249.98 (of) -249.997 (the) -249.988 (feature) -250.002 (maps\056) ] TJ /R36 9.9626 Tf -9.96211 -19.825 Td <0f> Tj /R26 9.9626 Tf 9.96211 0 Td [ (Our) -283.007 (method) -282.002 (is) -283 (able) -283.009 (to) -283.002 (produce) -281.982 (relati) 24.986 (v) 14.9828 (ely) -283.002 (good) -282.992 (uni) 24.9958 (v) 14.9828 (er) 19.9869 (\055) ] TJ T* [ (sal) -295 (adv) 14.9828 (ersarial) -295.01 (e) 15.0122 (xamples) -294.985 (from) -295 (a) -295.995 (relati) 24.986 (v) 14.9828 (ely) -295 (small) -294.98 (num\055) ] TJ T* [ (ber) -250 (of) -249.995 (images) -250.015 (from) -249.988 (a) -250.002 (dataset\056) ] TJ /R36 9.9626 Tf -9.96211 -19.825 Td <0f> Tj /R26 9.9626 Tf 9.96211 0 Td [ (W) 79.9866 (e) -230.986 (in) 40.0056 (v) 14.9828 (estig) 5.00162 (ate) -230.003 (a) -230.986 (correlation) -229.986 (between) -231.015 (the) -231.01 (lar) 17.997 (gest) ] TJ /R32 9.9626 Tf 191.014 0 Td [ (\050) -0.90181 ] TJ /R34 9.9626 Tf 3.87383 0 Td [ (p) -0.10292 (\073) -167.781 (q) -0.40189 ] TJ /R32 9.9626 Tf 14.2449 0 Td [ (\051) -0.90181 ] TJ /R26 9.9626 Tf 3.875 0 Td (\055) Tj -213.008 -11.9551 Td [ (singular) -419.001 (v) 24.9811 (alue) -420.006 (and) -418.984 (the) -418.979 (fooling) -420.018 (rate) -418.994 (of) -418.989 (the) -419.999 (generated) ] TJ ET Q Q Q q q 1 1 1 rg /a0 gs 48.406 786.422 515.188 -52.699 re f q /s5 gs /x6 Do Q q /s7 gs /x8 Do Q q /s9 gs /x10 Do Q q /s11 gs /x12 Do Q Q Q Q q 1 0 0 1 0 0 cm BT /F1 12 Tf 14.4 TL ET 1 1 1 rg n 270 32 72 14 re f* 0.5 0.5 0.5 rg BT /F2 9 Tf 10.8 TL ET BT 1 0 0 1 297 35 Tm (8562) Tj T* ET Q endstream endobj 14 0 obj << /Filter /FlateDecode /Resources << /ExtGState << /a0 << /CA 1 /ca 1 >> >> /XObject << /x18 15 0 R >> >> /Length 28 /Group << /Type /Group /S /Transparency /CS /DeviceRGB /I true >> /BBox [ 78 746 96 765 ] /Type /XObject /Subtype /Form >> stream x+O4PH/VЯ0Pp 0 endstream endobj 15 0 obj << /Filter /FlateDecode /Resources 16 0 R /Length 107 /Type /XObject /BBox [ 78 746 96 765 ] /Subtype /Form >> stream xe AC̬wʠ =p,?]%+H-
Jc "82w8VSnGW;"
endstream
endobj
16 0 obj
<<
/ExtGState <<
/a0 <<
/CA 1
/ca 1
>>
>>
>>
endobj
17 0 obj
<<
/Filter /FlateDecode
/Resources <<
/ExtGState <<
/a0 <<
/CA 1
/ca 1
>>
>>
/XObject <<
/x15 18 0 R
>>
>>
/Length 28
/Group <<
/Type /Group
/S /Transparency
/CS /DeviceRGB
/I true
>>
/BBox [ 67 752 84 775 ]
/Type /XObject
/Subtype /Form
>>
stream
x+O4PH/VЯ04Up
0
endstream
endobj
18 0 obj
<<
/Filter /FlateDecode
/Resources 19 0 R
/Length 228
/Type /XObject
/BBox [ 67 752 84 775 ]
/Subtype /Form
>>
stream
xeQKn!s ?FPav6R٪TS.
b];15YyR
{7QL.\:Rv/x9l+L7h%1!}i/AI(kz"U&,YO![R hg{3}4/GyYF:!w}Gn+'xJcO9i뽼_-:`
endstream
endobj
19 0 obj
<<
/ExtGState <<
/a0 <<
/CA 1
/ca 1
>>
>>
>>
endobj
20 0 obj
<<
/Filter /FlateDecode
/Resources <<
/ExtGState <<
/a0 <<
/CA 1
/ca 1
>>
>>
/XObject <<
/x24 21 0 R
>>
>>
/Length 28
/Group <<
/Type /Group
/S /Transparency
/CS /DeviceRGB
/I true
>>
/BBox [ 132 751 480 772 ]
/Type /XObject
/Subtype /Form
>>
stream
x+O4PH/VЯ02Qp
0
endstream
endobj
21 0 obj
<<
/Filter /FlateDecode
/Resources 22 0 R
/Length 53223
/Type /XObject
/BBox [ 132 751 480 772 ]
/Subtype /Form
>>
stream
xtI:6%Q㨈?7rA= u%6 ?Y(WbWo{B>9
x`Znϳ|8{3?0x*z ǃ|,@:w>`c|*ϻⳅKO3`g
:_|}}><.6`Z{{3]#<_o"~:ͺgk7/Ұ@|K yp ]03ʷCmş8˽Y?>(3!Bwqs.Z8,~~=rMT̩y+/*w: uBZ_`ߵp`%M?ɝ1ɳw=vDۉy&xb4Q>d@ sg~lA