面向鲁棒神经网络的稀疏编码前端
机器学习
2021-04-13 v1 机器学习
摘要
深度神经网络已知易受微小、对抗性精心构造的扰动所攻击。当前针对这些对抗攻击最有效的防御方法是对抗训练的各种变体。在本文中,我们引入一种仅在干净图像上训练的截然不同防御:基于稀疏编码的前端,其在对抗攻击到达分类器之前显著削弱之。我们在 CIFAR-10 数据集上针对广泛攻击类型(包括 Linf、L2 与 L1 有界攻击)评估了我们的防御,展示了其作为通用防御方法的潜力。
引用
@article{arxiv.2104.05353,
title = {Sparse Coding Frontend for Robust Neural Networks},
author = {Can Bakiskan and Metehan Cekic and Ahmet Dundar Sezer and Upamanyu Madhow},
journal= {arXiv preprint arXiv:2104.05353},
year = {2021}
}
备注
International Conference on Learning Representations (ICLR) 2021 Workshop on Security and Safety in Machine Learning Systems