Skip to main content
. Author manuscript; available in PMC: 2021 Feb 28.
Published in final edited form as: Neurocomputing (Amst). 2019 Oct 31;379:370–378. doi: 10.1016/j.neucom.2019.10.085

Figure 4:

Figure 4:

Attacks that aim to minimize predicted age. The x-axis limits the amount of noise injected, while the y-axis shows the corresponding impact, measured by deviation from original prediction. Left: adversarial perturbations bounded by the l metric. Middle: adversarial perturbations bounded by the l2 metric. Right: adversarial perturbations bounded by the l0 metric.