Pith. sign in

REVIEW

Certified Defenses for Adversarial Patches

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2003.06693 v2 pith:JZMHPL5E submitted 2020-03-14 cs.CR cs.LGstat.ML

classification cs.CRcs.LGstat.ML
keywords attackscertifiedpatchadversarialdefensesdefensepatchespropose
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Adversarial patch attacks are among one of the most practical threat models against real-world computer vision systems. This paper studies certified and empirical defenses against patch attacks. We begin with a set of experiments showing that most existing defenses, which work by pre-processing input images to mitigate adversarial patches, are easily broken by simple white-box adversaries. Motivated by this finding, we propose the first certified defense against patch attacks, and propose faster methods for its training. Furthermore, we experiment with different patch shapes for testing, obtaining surprisingly good robustness transfer across shapes, and present preliminary results on certified defense against sparse attacks. Our complete implementation can be found on: https://github.com/Ping-C/certifiedpatchdefense.

Discussion (0). Sign in to comment.

Pith tools