paper-with-me

Papers

Real-time Detection of Practical Universal Adversarial Perturbations

2021-05-16 · Kenneth T. Co, Luis Muñoz-González, Leslie Kanthan, Emil C. Lupu

Universal Adversarial Perturbations (UAPs) are a prominent class of adversarial examples that exploit the systemic vulnerabilities and enable physically realizable and robust attacks against Deep Neural Networks (DNNs). UAPs generalize across many different inputs; this leads to realistic and effective attacks that can be applied at scale. In this paper we propose HyperNeuron, an efficient and scalable algorithm that allows for the real-time detection of UAPs by identifying suspicious neuron hyper-activations. Our results show the effectiveness of HyperNeuron on multiple tasks (image classification, object detection), against a wide variety of universal attacks, and in realistic scenarios, like perceptual ad-blocking and adversarial patches. HyperNeuron is able to simultaneously detect both adversarial mask and patch UAPs with comparable or better performance than existing UAP defenses whilst introducing a significantly reduced latency of only 0.86 milliseconds per image. This suggests that many realistic and practical universal attacks can be reliably mitigated in real-time, which shows promise for the robust deployment of machine learning systems.

📄 PDF Abstract BibTeX arXiv:2105.07334

Code (0)

등록된 구현이 없습니다.

Tasks

Blockingimage-classificationImage Classificationobject-detectionObject Detection

Similar Papers 제목 키워드 기반

Universal and Efficient Detection of Adversarial Data through Nonuniform Impact on Network Layers

2025-06-25 · Furkan Mumcu, Yasin Yilmaz

Deep Neural Networks (DNNs) are notoriously vulnerable to adversarial input designs with limited noise budgets. While numerous successful attacks with subtle modifications to original input have been proposed, defense te…

Jacobian Regularization for Mitigating Universal Adversarial Perturbations

2021-04-21 · Kenneth T. Co, David Martinez Rego, Emil C. Lupu

Universal Adversarial Perturbations (UAPs) are input perturbations that can fool a neural network on large sets of data. They are a class of attacks that represents a significant threat as they facilitate realistic, prac…

Attack on practical speaker verification system using universal adversarial perturbations

2021-05-19 · Weiyi Zhang, Shuning Zhao, Le Liu, Jianmin Li 외

In authentication scenarios, applications of practical speaker verification systems usually require a person to read a dynamic authentication text. Previous studies played an audio adversarial example as a digital signal…

Real-World Adversarial AttackRoom Impulse Response (RIR)Speaker Verificationspeech-recognition+1

LiBRe: A Practical Bayesian Approach to Adversarial Detection

2021-03-27 · CVPR 2021 1 · Zhijie Deng, Xiao Yang, Shizhen Xu, Hang Su 외

Despite their appealing flexibility, deep neural networks (DNNs) are vulnerable against adversarial examples. Various adversarial defense strategies have been proposed to resolve this problem, but they typically demonstr…

Adversarial DefenseUncertainty Quantification

Adversarial Threats to DeepFake Detection: A Practical Perspective

2020-11-19 · Paarth Neekhara, Brian Dolhansky, Joanna Bitton, Cristian Canton Ferrer

Facially manipulated images and videos or DeepFakes can be used maliciously to fuel misinformation or defame individuals. Therefore, detecting DeepFakes is crucial to increase the credibility of social media platforms an…

DeepFake DetectionFace SwappingMisinformation