Pith. sign in

REVIEW 1 cited by

Fighting Gradients with Gradients: Dynamic Defenses against Adversarial Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2105.08714 v1 pith:ZK44HFWU submitted 2021-05-18 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords defensesattacksdentmodelsadversarialcifar-10dynamicexisting
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Adversarial attacks optimize against models to defeat defenses. Existing defenses are static, and stay the same once trained, even while attacks change. We argue that models should fight back, and optimize their defenses against attacks at test time. We propose dynamic defenses, to adapt the model and input during testing, by defensive entropy minimization (dent). Dent alters testing, but not training, for compatibility with existing models and train-time defenses. Dent improves the robustness of adversarially-trained defenses and nominally-trained models against white-box, black-box, and adaptive attacks on CIFAR-10/100 and ImageNet. In particular, dent boosts state-of-the-art defenses by 20+ points absolute against AutoAttack on CIFAR-10 at $\epsilon_\infty$ = 8/255.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Rectifying Adversarial Sample with Low Entropy Prior for Test-Time Defense

    cs.CV 2025-07 conditional novelty 5.0 of 10

    A two-stage entropy-maximization then entropy-minimization rectification, guided by a low-entropy prior of adversarial examples, improves test-time defense generalization on several benchmarks.

Pith tools