English

L 1-norm double backpropagation adversarial defense

Machine Learning 2019-03-06 v1 Neural and Evolutionary Computing

Abstract

Adversarial examples are a challenging open problem for deep neural networks. We propose in this paper to add a penalization term that forces the decision function to be at in some regions of the input space, such that it becomes, at least locally, less sensitive to attacks. Our proposition is theoretically motivated and shows on a first set of carefully conducted experiments that it behaves as expected when used alone, and seems promising when coupled with adversarial training.

Keywords

Cite

@article{arxiv.1903.01715,
  title  = {L 1-norm double backpropagation adversarial defense},
  author = {Ismaïla Seck and Gaëlle Loosli and Stephane Canu},
  journal= {arXiv preprint arXiv:1903.01715},
  year   = {2019}
}

Comments

ESANN - European Symposium on Artificial Neural Networks, Computational Intelligence and Machine Learning, Apr 2019, Bruges, France

R2 v1 2026-06-23T07:58:27.467Z