pith. sign in

On the Robustness of the CVPR 2018 White-Box Adversarial Example Defenses

2 Pith papers cite this work. Polarity classification is still indexing.

2 Pith papers citing it
abstract

Neural networks are known to be vulnerable to adversarial examples. In this note, we evaluate the two white-box defenses that appeared at CVPR 2018 and find they are ineffective: when applying existing techniques, we can reduce the accuracy of the defended models to 0%.

fields

cs.CR 2

years

2019 2

verdicts

UNVERDICTED 2

representative citing papers

Stateful Detection of Black-Box Adversarial Attacks

cs.CR · 2019-07-12 · unverdicted · novelty 7.0

The paper argues for stateful defenses over stateless ones to detect adversarial example generation via query history and introduces query blinding as a counter-attack.

citing papers explorer

Showing 2 of 2 citing papers.