Semantic-Preserving

SPAT: Semantic-Preserving Adversarial Transformation for Perceptually Similar Adversarial Examples

We propose a novel Semantic-Preserving Adversarial Transformation (SPAT) framework which facilitates an advantageous trade-off between the attack success rate and the perceptual similarity between the benign and adversarial examples.