English

ATHENA: A Framework based on Diverse Weak Defenses for Building Adversarial Defense

Machine Learning 2020-10-20 v2 Cryptography and Security Machine Learning

Abstract

There has been extensive research on developing defense techniques against adversarial attacks; however, they have been mainly designed for specific model families or application domains, therefore, they cannot be easily extended. Based on the design philosophy of ensemble of diverse weak defenses, we propose ATHENA---a flexible and extensible framework for building generic yet effective defenses against adversarial attacks. We have conducted a comprehensive empirical study to evaluate several realizations of ATHENA with four threat models including zero-knowledge, black-box, gray-box, and white-box. We also explain (i) why diversity matters, (ii) the generality of the defense framework, and (iii) the overhead costs incurred by ATHENA.

Cite

@article{arxiv.2001.00308,
  title  = {ATHENA: A Framework based on Diverse Weak Defenses for Building Adversarial Defense},
  author = {Ying Meng and Jianhai Su and Jason O'Kane and Pooyan Jamshidi},
  journal= {arXiv preprint arXiv:2001.00308},
  year   = {2020}
}

Comments

18 pages, 32 figures

R2 v1 2026-06-23T13:01:01.221Z