Pith. sign in

REVIEW

Regularized Ensembles and Transferability in Adversarial Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1812.01821 v1 pith:CCHI32X3 submitted 2018-12-05 cs.LG cs.CVstat.ML

classification cs.LGcs.CVstat.ML
keywords adversarialmodelstransferabilityensembleexamplesregularizedanotherarray
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Despite the considerable success of convolutional neural networks in a broad array of domains, recent research has shown these to be vulnerable to small adversarial perturbations, commonly known as adversarial examples. Moreover, such examples have shown to be remarkably portable, or transferable, from one model to another, enabling highly successful black-box attacks. We explore this issue of transferability and robustness from two dimensions: first, considering the impact of conventional $l_p$ regularization as well as replacing the top layer with a linear support vector machine (SVM), and second, the value of combining regularized models into an ensemble. We show that models trained with different regularizers present barriers to transferability, as does partial information about the models comprising the ensemble.

Discussion (0). Continue with ORCID to comment.

Pith tools