English

On the Robustness of the CVPR 2018 White-Box Adversarial Example Defenses

Computer Vision and Pattern Recognition 2018-04-11 v1 Cryptography and Security Machine Learning Machine Learning

Abstract

Neural networks are known to be vulnerable to adversarial examples. In this note, we evaluate the two white-box defenses that appeared at CVPR 2018 and find they are ineffective: when applying existing techniques, we can reduce the accuracy of the defended models to 0%.

Keywords

Cite

@article{arxiv.1804.03286,
  title  = {On the Robustness of the CVPR 2018 White-Box Adversarial Example Defenses},
  author = {Anish Athalye and Nicholas Carlini},
  journal= {arXiv preprint arXiv:1804.03286},
  year   = {2018}
}