Research Article

Detection Mechanisms of One-Pixel Attack

Table 1

Notations.

NotationsMeaning

Output labels in a DNN model
The original label
The target label of a one-pixel attack
The function that applies a trigger to an image
The original image
The modified image
A pixel of and represents a pixel of
and are the and coordinates of the pixel, respectively, and is the color channel
A trigger of an image
The loss function measuring classification error
An element of the candidate solution
Maximum iteration numbers