<?xml version="1.0"?>
<metadata xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/"><dc:title>An experimental evaluation of adversarial examples and methods of defense</dc:title><dc:creator>Šircelj,	Jaka	(Avtor)
	</dc:creator><dc:creator>Skočaj,	Danijel	(Mentor)
	</dc:creator><dc:subject>adversarial examples</dc:subject><dc:subject>neural networks</dc:subject><dc:subject>deep learning</dc:subject><dc:subject>image classification</dc:subject><dc:description>In this thesis we perform an experimental analysis and evaluation of different methods for creating adversarial examples, and learn how these affect different types of image classifiers, with the intent to obtain a better understanding of adversarial examples. The adversarial methods are hard to compare, since they use different types of parameters. We introduce a novel visualization technique, called accuracy-perturbation curve, that allows us to perform our comparison much more in depth, without the need to find optimal parameters. With this technique we also evaluate the successfulness of adversarial training as a defensive method. The results showed that radial basis function network classifiers possess an intrinsic property that makes them stronger on adversarial examples, compared to other classifiers, like CNNs, even though they perform poorly on clean images. Also, we noticed a weak correlation between the classifiers ability to generalize and its robustness against attacks.</dc:description><dc:date>2019</dc:date><dc:date>2019-09-30 13:50:14</dc:date><dc:type>Magistrsko delo/naloga</dc:type><dc:identifier>111417</dc:identifier><dc:identifier>VisID: 22583</dc:identifier><dc:identifier>COBISS_ID: 1538387139</dc:identifier><dc:language>sl</dc:language></metadata>
