Pith. sign in

REVIEW 1 cited by

Unfolding Local Growth Rate Estimates for (Almost) Perfect Adversarial Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2212.06776 v5 pith:GVSMZMYF submitted 2022-12-13 cs.CV cs.CR

Unfolding Local Growth Rate Estimates for (Almost) Perfect Adversarial Detection

classification cs.CV cs.CR
keywords adversarialnetworksalmostapproachesattacksbeendatadetection
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
read the original abstract

Convolutional neural networks (CNN) define the state-of-the-art solution on many perceptual tasks. However, current CNN approaches largely remain vulnerable against adversarial perturbations of the input that have been crafted specifically to fool the system while being quasi-imperceptible to the human eye. In recent years, various approaches have been proposed to defend CNNs against such attacks, for example by model hardening or by adding explicit defence mechanisms. Thereby, a small "detector" is included in the network and trained on the binary classification task of distinguishing genuine data from data containing adversarial perturbations. In this work, we propose a simple and light-weight detector, which leverages recent findings on the relation between networks' local intrinsic dimensionality (LID) and adversarial attacks. Based on a re-interpretation of the LID measure and several simple adaptations, we surpass the state-of-the-art on adversarial detection by a significant margin and reach almost perfect results in terms of F1-score for several networks and datasets. Sources available at: https://github.com/adverML/multiLID

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. GLID: Gated Local Intrinsic Dimension Repairs the Blind Spots of Face-Forgery Detectors

    cs.CR 2026-07 conditional novelty 6.0

    A gated, training-free local-intrinsic-dimension profile from a frozen ViT repairs face-forgery detectors on unseen GAN and diffusion axes, lifting generation-family AUC by +0.084.