Seeing is Not Always Believing: the Space of Harmless Perturbations

Lu Chen,Shaofeng Li,Benhao Huang,Fan Yang,Zheng Li,Jie Li,Yuan Luo
2024-01-01
Abstract:In the context of deep neural networks, we expose the existence of a harmlessperturbation space, where perturbations leave the network output entirelyunaltered. Perturbations within this harmless perturbation space, regardless oftheir magnitude when applied to images, exhibit no impact on the network'soutputs of the original images. Specifically, given any linear layer within thenetwork, where the input dimension n exceeds the output dimension m, wedemonstrate the existence of a continuous harmless perturbation subspace with adimension of (n-m). Inspired by this, we solve for a family of generalperturbations that consistently influence the network output, irrespective oftheir magnitudes. With these theoretical findings, we explore the applicationof harmless perturbations for privacy-preserving data usage. Our work revealsthe difference between DNNs and human perception that the significantperturbations captured by humans may not affect the recognition of DNNs. As aresult, we utilize this gap to design a type of harmless perturbation that ismeaningless for humans while maintaining its recognizable features for DNNs.
What problem does this paper attempt to address?