Pith. sign in

REVIEW 2 cited by

Towards Robust Neural Networks via Random Self-ensemble

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1712.00673 v2 pith:3H632ZAS submitted 2017-12-02 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords neuralaccuracynetworkrandomalgorithmattackdefenseensemble
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
abstract

Recent studies have revealed the vulnerability of deep neural networks: A small adversarial perturbation that is imperceptible to human can easily make a well-trained deep neural network misclassify. This makes it unsafe to apply neural networks in security-critical applications. In this paper, we propose a new defense algorithm called Random Self-Ensemble (RSE) by combining two important concepts: {\bf randomness} and {\bf ensemble}. To protect a targeted model, RSE adds random noise layers to the neural network to prevent the strong gradient-based attacks, and ensembles the prediction over random noises to stabilize the performance. We show that our algorithm is equivalent to ensemble an infinite number of noisy models $f_\epsilon$ without any additional memory overhead, and the proposed training procedure based on noisy stochastic gradient descent can ensure the ensemble model has a good predictive capability. Our algorithm significantly outperforms previous defense techniques on real data sets. For instance, on CIFAR-10 with VGG network (which has 92\% accuracy without any attack), under the strong C\&W attack within a certain distortion tolerance, the accuracy of unprotected model drops to less than 10\%, the best previous defense technique has $48\%$ accuracy, while our method still has $86\%$ prediction accuracy under the same level of attack. Finally, our method is simple and easy to integrate into any neural network.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Efficient Bidirectional Neural Machine Translation

    cs.CL 2019-08 conditional novelty 6.0 of 10

    A single encoder-decoder trained with both decoding directions beats a unidirectional Transformer by 0.8 to 1.3 BLEU and saves about half the parameters of a two-model ensemble.

  2. Protecting Neural Networks with Hierarchical Random Switching: Towards Better Robustness-Accuracy Trade-off for Stochastic Defenses

    cs.LG 2019-08 conditional novelty 6.0 of 10

    A stochastic neural network defense using randomly switched parallel weight channels achieves a high defense-per-accuracy-drop ratio on MNIST and CIFAR-10 and is reported as the first defense against adversarial repro...

Pith tools