REVIEW 2 cited by
Efficient Defenses Against Adversarial Attacks
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Following the recent adoption of deep neural networks (DNN) accross a wide range of applications, adversarial attacks against these models have proven to be an indisputable threat. Adversarial samples are crafted with a deliberate intention of undermining a system. In the case of DNNs, the lack of better understanding of their working has prevented the development of efficient defenses. In this paper, we propose a new defense method based on practical observations which is easy to integrate into models and performs better than state-of-the-art defenses. Our proposed solution is meant to reinforce the structure of a DNN, making its prediction more stable and less likely to be fooled by adversarial samples. We conduct an extensive experimental study proving the efficiency of our method against multiple attacks, comparing it to numerous defenses, both in white-box and black-box setups. Additionally, the implementation of our method brings almost no overhead to the training procedure, while maintaining the prediction performance of the original model on clean samples.
Forward citations
Cited by 2 Pith papers
-
BlurNet: Defense by Filtering the Feature Maps
Low-pass filtering or total-variation regularization of first-layer feature maps reduces RP2 adversarial sticker attack success on LISA traffic-sign classifiers from 90% to 20% worst-case, with a 5-14% clean accuracy drop.
-
Robustifying deep networks for image segmentation
Adversarial perturbations based on gradient methods reduce brain tumor segmentation Dice scores by up to 65 percent, and defensive distillation outperforms adversarial training while all defenses still underperform on...
Discussion (0). Continue with ORCID to comment.