paper-with-me

홈 › Papers

White-Box Adversarial Defense via Self-Supervised Data Estimation

2019-09-13 · Zudi Lin, Hanspeter Pfister, Ziming Zhang

In this paper, we study the problem of how to defend classifiers against adversarial attacks that fool the classifiers using subtly modified input data. In contrast to previous works, here we focus on the white-box adversarial defense where the attackers are granted full access to not only the classifiers but also defenders to produce as strong attacks as possible. In such a context we propose viewing a defender as a functional, a higher-order function that takes functions as its argument to represent a function space, rather than fixed functions conventionally. From this perspective, a defender should be realized and optimized individually for each adversarial input. To this end, we propose RIDE, an efficient and provably convergent self-supervised learning algorithm for individual data estimation to protect the predictions from adversarial attacks. We demonstrate the significant improvement of adversarial defense performance on image recognition, eg, 98%, 76%, 43% test accuracy on MNIST, CIFAR-10, and ImageNet datasets respectively under the state-of-the-art BPDA attacker.

📄 PDF Abstract BibTeX arXiv:1909.06271

Code (1)

zudi-lin/RIDE pytorch

Tasks

Adversarial DefenseSelf-Supervised Learning

Similar Papers 제목 키워드 기반

Improving Adversarial Defense with Self-supervised Test-time Fine-tuning

2021-09-29 · Zhichao Huang, Chen Liu, Mathieu Salzmann, Sabine Süsstrunk 외

Although adversarial training and its variants currently constitute the most effective way to achieve robustness against adversarial attacks, their poor generalization limits their performance on the test samples. In thi…

Adversarial Defense

MIXPGD: Hybrid Adversarial Training for Speech Recognition Systems

2023-03-10 · Aminul Huq, Weiyi Zhang, Xiaolin Hu

Automatic speech recognition (ASR) systems based on deep neural networks are weak against adversarial perturbations. We propose mixPGD adversarial training method to improve the robustness of the model for ASR systems. I…

Adversarial AttackAutomatic Speech RecognitionAutomatic Speech Recognition (ASR)speech-recognition+1

AuxBlocks: Defense Adversarial Example via Auxiliary Blocks

2019-02-18 · Yueyao Yu, Pengfei Yu, Wenye Li

Deep learning models are vulnerable to adversarial examples, which poses an indisputable threat to their applications. However, recent studies observe gradient-masking defenses are self-deceiving methods if an attacker c…

Benchmarking adversarial attacks and defenses for time-series data

2020-08-30 · Shoaib Ahmed Siddiqui, Andreas Dengel, Sheraz Ahmed

The adversarial vulnerability of deep networks has spurred the interest of researchers worldwide. Unsurprisingly, like images, adversarial examples also translate to time-series data as they are an inherent weakness of t…

Adversarial DefenseBenchmarkingTime SeriesTime Series Analysis

NCIS: Neural Contextual Iterative Smoothing for Purifying Adversarial Perturbations

2021-06-22 · ICML Workshop AML 2021 7 · Sungmin Cha, Naeun Ko, Youngjoon Yoo, Taesup Moon

We propose a novel and effective purification based adversarial defense method against pre-processor blind white- and black-box attacks. Our method is computationally efficient and trained only with self-supervised learn…

Adversarial DefenseAdversarial Robustnessimage-classificationImage Classification+1