Sparse Coding Frontend for Robust Neural Networks
Bakiskan, Can, Cekic, Metehan, Sezer, Ahmet Dundar, Madhow, Upamanyu
Deep Neural Networks are known to be vulnerable to small, adversarially crafted, perturbations. The current most effective defense methods against these adversarial attacks are variants of adversarial training. In this paper, we introduce a radically different defense trained only on clean images: a sparse coding based front end which significantly attenuates adversarial attacks before they reach the classifier. Deep neural networks (DNNs) are known to be vulnerable to small, adversarially designed perturbations (Biggio et al., 2013; Szegedy et al., 2014). Since the discovery of such adversarial attacks, researchers have tried various defense strategies such as adversarial training (Madry et al., 2018; Zhang et al., 2019), constraining Lipschitz constant (Cisse et al., 2017), randomized smoothing (Cohen et al., 2019), and preprocessing methods (Guo et al., 2017; Yang et al., 2019).
Apr-12-2021
- Country:
- North America > United States
- New York > New York County
- New York City (0.04)
- California > Santa Barbara County
- Santa Barbara (0.14)
- New York > New York County
- Asia > Middle East
- Jordan (0.04)
- North America > United States
- Genre:
- Research Report (0.50)
- Industry:
- Information Technology > Security & Privacy (0.75)
- Government > Military (0.75)
- Technology: