paper-with-me

홈 › Papers

Adversarial Defense by Stratified Convolutional Sparse Coding

2018-11-30 · CVPR 2019 6 · Bo Sun, Nian-hsuan Tsai, Fangchen Liu, Ronald Yu, Hao Su

We propose an adversarial defense method that achieves state-of-the-art performance among attack-agnostic adversarial defense methods while also maintaining robustness to input resolution, scale of adversarial perturbation, and scale of dataset size. Based on convolutional sparse coding, we construct a stratified low-dimensional quasi-natural image space that faithfully approximates the natural image space while also removing adversarial perturbations. We introduce a novel Sparse Transformation Layer (STL) in between the input image and the first layer of the neural network to efficiently project images into our quasi-natural image space. Our experiments show state-of-the-art performance of our method compared to other attack-agnostic adversarial defense methods in various adversarial settings.

📄 PDF Abstract BibTeX arXiv:1812.00037

Code (1)

gitbosun/advdefense_csc

Tasks

Adversarial Defense

Similar Papers 제목 키워드 기반

Sparse Coding Frontend for Robust Neural Networks

2021-04-12 · Can Bakiskan, Metehan Cekic, Ahmet Dundar Sezer, Upamanyu Madhow

Deep Neural Networks are known to be vulnerable to small, adversarially crafted, perturbations. The current most effective defense methods against these adversarial attacks are variants of adversarial training. In this p…

Stratified Adversarial Robustness with Rejection

2023-05-02 · Jiefeng Chen, Jayaram Raghuram, Jihye Choi, Xi Wu 외

Recently, there is an emerging interest in adversarially training a classifier with a rejection option (also known as a selective classifier) for boosting adversarial robustness. While rejection can incur a cost in many …

Adversarial RobustnessRobust classification

Provable Defense Framework for LLM Jailbreaks via Noise-Augumented Alignment

2026-02-02 · Zehua Cheng, Jianwei Yang, Wei Dai, Jiahao Sun arxiv

Large Language Models (LLMs) remain vulnerable to adaptive jailbreaks that easily bypass empirical defenses like GCG. We propose a framework for certifiable robustness that shifts safety guarantees from single-pass infer…

Improving Robustness to Model Inversion Attacks via Sparse Coding Architectures

2024-03-21 · Sayanton V. Dibbo, Adam Breuer, Juston Moore, Michael Teti

Recent model inversion attack algorithms permit adversaries to reconstruct a neural network's private and potentially sensitive training data by repeatedly querying the network. In this work, we develop a novel network a…

DenoisingImage DenoisingObject RecognitionSSIM

Adversarial Attacks on Spiking Convolutional Neural Networks for Event-based Vision

2021-10-06 · Julian Büchel, Gregor Lenz, Yalun Hu, Sadique Sheik 외

Event-based dynamic vision sensors provide very sparse output in the form of spikes, which makes them suitable for low-power applications. Convolutional spiking neural networks model such event-based data and develop the…

Adversarial AttackEvent-based vision