Goto

Collaborating Authors

 anti-bandit neural architecture search


Anti-Bandit Neural Architecture Search for Model Defense

#artificialintelligence

In order to resist attacks, various methods have been proposed. A category of defense methods improve network's training regime to counter adversarial attacks. The most common method is adversarial training [23, 31] with adversarial examples added to the training data. In [29], a defense method called Min-Max optimization is introduced to augment the training data with first-order attack samples. There are also some model defense methods that target at removing adversarial perturbation by transforming the input images before feeding them to the network [24, 1, 18].