paper-with-me

홈 › Papers

An Empirical Investigation of Randomized Defenses against Adversarial Attacks

2019-09-12 · Yannik Potdevin, Dirk Nowotka, Vijay Ganesh

In recent years, Deep Neural Networks (DNNs) have had a dramatic impact on a variety of problems that were long considered very difficult, e. g., image classification and automatic language translation to name just a few. The accuracy of modern DNNs in classification tasks is remarkable indeed. At the same time, attackers have devised powerful methods to construct specially-crafted malicious inputs (often referred to as adversarial examples) that can trick DNNs into mis-classifying them. What is worse is that despite the many defense mechanisms proposed to protect DNNs against adversarial attacks, attackers are often able to circumvent these defenses, rendering them useless. This state of affairs is extremely worrying, especially since machine learning systems get adopted at scale. In this paper, we propose a scientific evaluation methodology aimed at assessing the quality, efficacy, robustness and efficiency of randomized defenses to protect DNNs against adversarial examples. Using this methodology, we evaluate a variety of defense mechanisms. In addition, we also propose a defense mechanism we call Randomly Perturbed Ensemble Neural Networks (RPENNs). We provide a thorough and comprehensive evaluation of the considered defense mechanisms against a white-box attacker model, six different adversarial attack methods and using the ILSVRC2012 validation data set.

📄 PDF Abstract BibTeX arXiv:1909.05580

Code (1)

ypotdevin/randomized-defenses 공식 구현

Tasks

Adversarial AttackGeneral Classificationimage-classificationImage Classification

Similar Papers 제목 키워드 기반

On Certifying Robustness against Backdoor Attacks via Randomized Smoothing

2020-02-26 · Binghui Wang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang Gong

Backdoor attack is a severe security threat to deep neural networks (DNNs). We envision that, like adversarial examples, there will be a cat-and-mouse game for backdoor attacks, i.e., new empirical defenses are developed…

Backdoor Attack

Rethinking Randomized Smoothing from the Perspective of Scalability

2023-12-19 · Anupriya Kumari, Devansh Bhardwaj, Sukrit Jindal

Machine learning models have demonstrated remarkable success across diverse domains but remain vulnerable to adversarial attacks. Empirical defense mechanisms often fail, as new attacks constantly emerge, rendering exist…

Survey

Defending against Whitebox Adversarial Attacks via Randomized Discretization

2019-03-25 · Yuchen Zhang, Percy Liang

Adversarial perturbations dramatically decrease the accuracy of state-of-the-art image classifiers. In this paper, we propose and analyze a simple and computationally efficient defense strategy: inject random Gaussian no…

Adversarial AttackGeneral Classification

Randomization matters. How to defend against strong adversarial attacks

2020-02-26 · Rafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre 외

Is there a classifier that ensures optimal robustness against all adversarial attacks? This paper answers this question by adopting a game-theoretic point of view. We show that adversarial attacks and defenses form an in…

Randomization matters How to defend against strong adversarial attacks

2020-01-01 · ICML 2020 1 · Rafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre 외

\emph{Is there a classifier that ensures optimal robustness against all adversarial attacks?} This paper answers this question by adopting a game-theoretic point of view. We show that adversarial attacks and defenses for…