Thwarting Adversarial Examples: An $L_0$-Robust Sparse Fourier Transform
Bafna, Mitali, Murtagh, Jack, Vyas, Nikhil
–Neural Information Processing Systems
Our techniques generalize to a wide range of linear transformations that are used in data analysis such as the Discrete Cosine and Sine transforms, the Hadamard transform, and their high-dimensional analogs. We use our algorithm to successfully defend against well known L adversaries in the setting of image classification.
Neural Information Processing Systems
Dec-31-2018
- Country:
- North America > United States
- Massachusetts > Middlesex County
- Cambridge (0.14)
- Oregon (0.14)
- Massachusetts > Middlesex County
- North America > United States
- Genre:
- Research Report (0.68)
- Industry:
- Information Technology > Security & Privacy (0.93)
- Technology: