paper-with-me

홈 › Papers

Robust Adversarial Learning via Sparsifying Front Ends

2018-10-24 · Soorya Gopalakrishnan, Zhinus Marzi, Metehan Cekic, Upamanyu Madhow, Ramtin Pedarsani

It is by now well-known that small adversarial perturbations can induce classification errors in deep neural networks. In this paper, we take a bottom-up signal processing perspective to this problem and show that a systematic exploitation of sparsity in natural data is a promising tool for defense. For linear classifiers, we show that a sparsifying front end is provably effective against $\ell_{\infty}$-bounded attacks, reducing output distortion due to the attack by a factor of roughly $K/N$ where $N$ is the data dimension and $K$ is the sparsity level. We then extend this concept to deep networks, showing that a "locally linear" model can be used to develop a theoretical foundation for crafting attacks and defenses. We also devise attacks based on the locally linear model that outperform the well-known FGSM attack. We supplement our theoretical results with experiments on the MNIST and CIFAR-10 datasets, showing the efficacy of the proposed sparsity-based defense schemes.

📄 PDF Abstract BibTeX arXiv:1810.10625

Code (1)

soorya19/sparsity-based-defenses 공식 구현 tf

Similar Papers 제목 키워드 기반

Combating Adversarial Attacks Using Sparse Representations

2018-03-11 · Soorya Gopalakrishnan, Zhinus Marzi, Upamanyu Madhow, Ramtin Pedarsani

It is by now well-known that small adversarial perturbations can induce classification errors in deep neural networks (DNNs). In this paper, we make the case that sparse representations of the input data are a crucial to…

General Classification

Sparsity-based Defense against Adversarial Attacks on Linear Classifiers

2018-01-15 · Zhinus Marzi, Soorya Gopalakrishnan, Upamanyu Madhow, Ramtin Pedarsani

Deep neural networks represent the state of the art in machine learning in a growing number of fields, including vision, speech and natural language processing. However, recent work raises important questions about the r…

Polarizing Front Ends for Robust CNNs

2020-02-22 · Can Bakiskan, Soorya Gopalakrishnan, Metehan Cekic, Upamanyu Madhow 외

The vulnerability of deep neural networks to small, adversarially designed perturbations can be attributed to their "excessive linearity." In this paper, we propose a bottom-up strategy for attenuating adversarial pertur…

Adversarial Humanities Benchmark: Results on Stylistic Robustness in Frontier Model Safety

2026-04-20 · Marcello Galisai, Susanna Cifani, Francesco Giarrusso, Piercosma Bisconti 외 arxiv

The Adversarial Humanities Benchmark (AHB) evaluates whether model safety refusals survive a shift away from familiar harmful prompt forms. Starting from harmful tasks drawn from MLCommons AILuminate, the benchmark rewri…

Learning Filter Bank Sparsifying Transforms

2018-03-06 · Luke Pfister, Yoram Bresler

Data is said to follow the transform (or analysis) sparsity model if it becomes sparse when acted on by a linear operator called a sparsifying transform. Several algorithms have been designed to learn such a transform di…

DenoisingImage Denoising