arrow
返回

FADER: Fast adversarial example rejection

delete2022-01-01
delete9
delete
OA
AI
F
Francesco Crecchi *
M
Marco Melis
A
Angelo Sotgiu
D
Davide Bacciu
B
Battista Biggio
DOI:10.1016/j.neucom.2021.10.082delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Deep neural networks are vulnerable to adversarial examples, i.e., carefully-crafted inputs that mislead classification at test time. Recent defenses have been shown to improve adversarial robustness by detect-ing anomalous deviations from legitimate training samples at different layer representations -a behavior normally exhibited by adversarial attacks. Despite technical differences, all aforementioned methods share a common backbone structure that we formalize and highlight in this contribution, as it can help in identifying promising research directions and drawbacks of existing methods. The first main contribu-tion of this work is the review of these detection methods in the form of a unifying framework designed to accommodate both existing defenses and newer ones to come. In terms of drawbacks, the overmen-tioned defenses require comparing input samples against an oversized number of reference prototypes, possibly at different representation layers, dramatically worsening the test-time efficiency. Besides, such defenses are typically based on ensembling classifiers with heuristic methods, rather than optimizing the whole architecture in an end-to-end manner to better perform detection. As a second main contribution of this work, we introduce FADER, a novel technique for speeding up detection-based methods. FADER overcome the issues above by employing RBF networks as detectors: by fixing the number of required prototypes, the runtime complexity of adversarial examples detectors can be controlled. Our experiments outline up to 73x prototypes reduction compared to analyzed detectors for MNIST dataset, up to 50x for CIFAR10 dataset, and up to 82x on ImageNet10 dataset respectively, without sacrificing classification accuracy on both clean and adversarial data. (c) 2021 Published by Elsevier B.V.
Keyword:
Adversarial machine learning
Adversarial examples
Detection
Evasion attacks
RBF networks
Deep learning
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Neurocomputing 封面图
Neurocomputing
IF:
6.5
论文数:
2.5W
被引数:
6.5W

机构

U
university of cagliari
学者数:
1.2W
论文数: 9.7K
被引数: 9
U
University of Pisa
学者数:
3.1W
论文数: 2.4W
被引数: 2.4W
引用论文

引用论文

Competitive redox-catalyzed migratory carbonyl insertion and .beta.-elimination in iron alkyl complexes
err2002-05-01
err0
PREAI
errRobert S. Bly; Gary S. Silverman; M. Mahmun Hossain; Ruta K. Bly
err分享
err收藏
Improved Interface Circuit for Enhancing the Power Output of a Vibration-Threshold-Triggered Piezoelectric Energy Harvester
err2020-07-25
err0
errOAAI
errJiqiang Liu; Junjie Yang; Ruofeng Han; Qisheng He; Dacheng Xu; Xinxin Li
err分享
err收藏
学者 查看更多内容