Fig. 2From: Attacking convolutional neural network using differential evolutionComparing one- and few-pixel attack. A visual comparison between the adversarial images generated by proposed attack and one-pixel attack. Since the former has control mechanisms embedded in the fitness function, the distortion it caused on single pixel is expected to be less perceptible than one-pixel attack. As can be seen, even if requiring perturbing more pixels, the proposed attack can have similar or better visual effect to one-pixel attack in practice which only few or even none of the perturbed pixels is noticeableBack to article page