Sparse Coding Frontend for Robust Neural Networks

Bakiskan, Can, Cekic, Metehan, Sezer, Ahmet Dundar, Madhow, Upamanyu

arXiv.org Machine Learning 

Deep Neural Networks are known to be vulnerable to small, adversarially crafted, perturbations. The current most effective defense methods against these adversarial attacks are variants of adversarial training. In this paper, we introduce a radically different defense trained only on clean images: a sparse coding based front end which significantly attenuates adversarial attacks before they reach the classifier. Deep neural networks (DNNs) are known to be vulnerable to small, adversarially designed perturbations (Biggio et al., 2013; Szegedy et al., 2014). Since the discovery of such adversarial attacks, researchers have tried various defense strategies such as adversarial training (Madry et al., 2018; Zhang et al., 2019), constraining Lipschitz constant (Cisse et al., 2017), randomized smoothing (Cohen et al., 2019), and preprocessing methods (Guo et al., 2017; Yang et al., 2019).

Duplicate Docs Excel Report

Title
None found

Similar Docs  Excel Report  more

TitleSimilaritySource
None found