paper-with-me

홈 › Papers

Optimal Transport Classifier: Defending Against Adversarial Attacks by Regularized Deep Embedding

2018-11-19 · Yao Li, Martin Renqiang Min, Wenchao Yu, Cho-Jui Hsieh, Thomas C. M. Lee, Erik Kruus

Recent studies have demonstrated the vulnerability of deep convolutional neural networks against adversarial examples. Inspired by the observation that the intrinsic dimension of image data is much smaller than its pixel space dimension and the vulnerability of neural networks grows with the input dimension, we propose to embed high-dimensional input images into a low-dimensional space to perform classification. However, arbitrarily projecting the input images to a low-dimensional space without regularization will not improve the robustness of deep neural networks. Leveraging optimal transport theory, we propose a new framework, Optimal Transport Classifier (OT-Classifier), and derive an objective that minimizes the discrepancy between the distribution of the true label and the distribution of the OT-Classifier output. Experimental results on several benchmark datasets show that, our proposed framework achieves state-of-the-art performance against strong adversarial attack methods.

📄 PDF Abstract BibTeX arXiv:1811.07950

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackGeneral Classification

Similar Papers 제목 키워드 기반

Defending against Machine Learning based Inference Attacks via Adversarial Examples: Opportunities and Challenges

2019-09-17 · Jinyuan Jia, Neil Zhenqiang Gong

As machine learning (ML) becomes more and more powerful and easily accessible, attackers increasingly leverage ML to perform automated large-scale inference attacks in various domains. In such an ML-equipped inference at…

BIG-bench Machine LearningInference Attack

Adversarial Risk via Optimal Transport and Optimal Couplings

2019-12-05 · ICML 2020 1 · Muni Sreenivas Pydi, Varun Jog

Modern machine learning algorithms perform poorly on adversarially manipulated data. Adversarial risk quantifies the error of classifiers in adversarial settings; adversarial classifiers minimize adversarial risk. In thi…

Binary Classification

Improving Adversarial Robustness to Sensitivity and Invariance Attacks with Deep Metric Learning

2022-11-04 · Anaelia Ovalle, Evan Czyzycki, Cho-Jui Hsieh

Intentionally crafted adversarial samples have effectively exploited weaknesses in deep neural networks. A standard method in adversarial robustness assumes a framework to defend against samples crafted by minimally pert…

Adversarial RobustnessMetric LearningSensitivity

Defending Against Adversarial Attacks by Leveraging an Entire GAN

2018-05-27 · Gokula Krishnan Santhanam, Paulina Grnarova

Recent work has shown that state-of-the-art models are highly vulnerable to adversarial perturbations of the input. We propose cowboy, an approach to detecting and defending against adversarial attacks by using both the …

DiffDefense: Defending against Adversarial Attacks via Diffusion Models

2023-09-07 · Hondamunige Prasanna Silva, Lorenzo Seidenari, Alberto del Bimbo

This paper presents a novel reconstruction method that leverages Diffusion Models to protect machine learning classifiers against adversarial attacks, all without requiring any modifications to the classifiers themselves…

Adversarial Defense