Skip to main content

Understanding How Adversarial Noise Affects Single Image Classification

  • Conference paper
  • First Online:
Smart Secure Systems – IoT and Analytics Perspective (ICIIT 2017)

Part of the book series: Communications in Computer and Information Science ((CCIS,volume 808))

Included in the following conference series:


In recent trends, computer vision applications have seen massive implementation of supervised learning with convolutional neural networks. In this paper, we have analyzed image classifiers and their classification accuracy. Also, we have measured their robustness upon introduction to various noise layers. Furthermore, we have implemented a generative adversarial network for the generator task of adversarial noise generation and the discriminator task of single image classification on the handwritten digits database. Our experiments are yielding progressive results and we have performed conditional and quantifiable evaluation of the generated samples.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
USD 39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions


  1. Goodfellow, I.J.: NIPS 2016 tutorial: generative adversarial networks. CoRR, abs/1701.00160 (2017)

    Google Scholar 

  2. Arjovsky, M., Bottou, L.: Towards principled methods for training generative adversarial networks. ArXiv e-prints, January 2017

    Google Scholar 

  3. Radford, A., Metz, L., Chintala, S.: Unsupervised representation learning with deep convolutional generative adversarial networks. CoRR, abs/1511.06434 (2015)

    Google Scholar 

  4. Springenberg, J.T., Dosovitskiy, A., Brox, T., Riedmiller, M.A.: Striving for simplicity: the all convolutional net. CoRR, abs/1412.6806 (2014)

    Google Scholar 

  5. Arjovsky, M., Chintala, S., Bottou, L.: Wasserstein GAN. ArXiv e-prints, January 2017

    Google Scholar 

  6. Hou, L., Yu, C.P., Samaras, D.: Squared earth mover’s distance-based loss for training deep neural networks. CoRR, abs/1611.05916 (2016)

    Google Scholar 

  7. Saatchi, Y., Wilson, A.G.: Bayesian GAN. ArXiv e-prints, May 2017

    Google Scholar 

  8. Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. ArXiv e-prints, December 2014

    Google Scholar 

  9. Papernot, N., McDaniel, P.D., Jha, S., Fredrikson, M., Celik, Z.B., Swami, A.: The limitations of deep learning in adversarial settings. CoRR, abs/1511.07528 (2015)

    Google Scholar 

  10. Dodge, S.F., Karam, L.J.: Understanding how image quality affects deep neural networks. CoRR, abs/1604.04004 (2016)

    Google Scholar 

  11. Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition. CoRR, abs/1409.1556 (2014)

    Google Scholar 

  12. Szegedy, C., Liu, W., Jia, Y., Sermanet, P., Reed, S.E., Anguelov, D., Erhan, D., Vanhoucke, V., Rabinovich, A.: Going deeper with convolutions. CoRR, abs/1409.4842 (2014)

    Google Scholar 

  13. Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial examples in the physical world. CoRR, abs/1607.02533 (2016)

    Google Scholar 

  14. Carlini, N., Wagner, D.A.: Towards evaluating the robustness of neural networks. CoRR, abs/1608.04644 (2016)

    Google Scholar 

  15. Huang, S.H., Papernot, N., Goodfellow, I.J., Duan, Y., Abbeel, P.: Adversarial attacks on neural network policies. CoRR, abs/1702.02284 (2017)

    Google Scholar 

  16. Feinman, R., Curtin, R.R., Shintre, S., Gardner, A.B.: Detecting adversarial samples from artifacts. ArXiv e-prints, March 2017

    Google Scholar 

  17. Krizhevsky, A., Sutskever, I., Hinton, G.E.: Imagenet classification with deep convolutional neural networks. In: Advances in Neural Information Processing Systems, pp. 1097–1105 (2012)

    Google Scholar 

  18. Kingma, D.P., Ba, J.: Adam: a method for stochastic optimization. CoRR, abs/1412.6980 (2014)

    Google Scholar 

  19. Metz, L., Poole, B., Pfau, D., Sohl-Dickstein, J.: Unrolled generative adversarial networks. CoRR, abs/1611.02163 (2016)

    Google Scholar 

  20. Hinton, G.E., Srivastava, N., Krizhevsky, A., Sutskever, I., Salakhutdinov, R.: Improving neural networks by preventing co-adaptation of feature detectors. CoRR, abs/1207.0580 (2012)

    Google Scholar 

Download references

Author information

Authors and Affiliations


Corresponding author

Correspondence to Rishabh Saxena .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2018 Springer Nature Singapore Pte Ltd.

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Adate, A., Saxena, R., Don.S (2018). Understanding How Adversarial Noise Affects Single Image Classification. In: Venkataramani, G., Sankaranarayanan, K., Mukherjee, S., Arputharaj, K., Sankara Narayanan, S. (eds) Smart Secure Systems – IoT and Analytics Perspective. ICIIT 2017. Communications in Computer and Information Science, vol 808. Springer, Singapore.

Download citation

  • DOI:

  • Published:

  • Publisher Name: Springer, Singapore

  • Print ISBN: 978-981-10-7634-3

  • Online ISBN: 978-981-10-7635-0

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics