Creating adversarial images for MNIST dataset.
Choose random image with label 2:
Adversarial image and probability after iteration 1:
Original label: 2; Original probability: 88.56145143508911 New label: 6; New probability with fake label: 76.18929743766785
Adversarial image and probability after iteration 2:
Original label: 2; Original probability: 88.56145143508911 New label: 6; New probability with fake label: 98.51791262626648
Adversarial image and probability after iteration 3:
Original label: 2; Original probability: 88.56145143508911 New label: 6; New probability with fake label: 99.8832643032074
Adversarial image and probability after iteration 4:
Original label: 2; Original probability: 88.56145143508911 New label: 6; New probability with fake label: 99.9846339225769
Adversarial image and probability after iteration 5:
Original label: 2; Original probability: 88.56145143508911 New label: 6; New probability with fake label: 99.9977707862854
So after iteration 5 our CNN is confident on 99.997% that number 2 is actually number 6