返回
FADER: Fast adversarial example rejection
DOI:10.1016/j.neucom.2021.10.082.png)
摘要
En 中文
Deep neural networks are vulnerable to adversarial examples, i.e., carefully-crafted inputs that mislead classification at test time. Recent defenses have been shown to improve adversarial robustness by detect-ing anomalous deviations from legitimate training samples at different layer representations -a behavior normally exhibited by adversarial attacks. Despite technical differences, all aforementioned methods share a common backbone structure that we formalize and highlight in this contribution, as it can help in identifying promising research directions and drawbacks of existing methods. The first main contribu-tion of this work is the review of these detection methods in the form of a unifying framework designed to accommodate both existing defenses and newer ones to come. In terms of drawbacks, the overmen-tioned defenses require comparing input samples against an oversized number of reference prototypes, possibly at different representation layers, dramatically worsening the test-time efficiency. Besides, such defenses are typically based on ensembling classifiers with heuristic methods, rather than optimizing the whole architecture in an end-to-end manner to better perform detection. As a second main contribution of this work, we introduce FADER, a novel technique for speeding up detection-based methods. FADER overcome the issues above by employing RBF networks as detectors: by fixing the number of required prototypes, the runtime complexity of adversarial examples detectors can be controlled. Our experiments outline up to 73x prototypes reduction compared to analyzed detectors for MNIST dataset, up to 50x for CIFAR10 dataset, and up to 82x on ImageNet10 dataset respectively, without sacrificing classification accuracy on both clean and adversarial data. (c) 2021 Published by Elsevier B.V.
Keyword:
Adversarial machine learning
Adversarial examples
Detection
Evasion attacks
RBF networks
Deep learning
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
6.5
论文数:
2.5W
被引数:
6.5W
机构
引用论文
Steady-State Solution for Dark States Using a Three-Level System in Coupled Quantum Dots耦合量子点中三能级系统暗态的稳态解
Do gradient-based explanations tell anything about adversarial robustness to android malware?基于梯度的解释是否能说明android恶意软件的对抗鲁棒性?
Welding characteristics of aluminum, copper, nickel and aluminum alloy with alumina coating using ultrasonic complex vibration welding equipments铝、铜、镍及铝合金氧化铝涂层超声复合振动焊接特性研究
Do Perceptions of Competence Mediate The Relationship Between Fundamental Motor Skill Proficiency and Physical Activity Levels of Children in Kindergarten?能力的感知是否可以介导幼儿园儿童的基本运动技能熟练程度与身体活动水平之间的关系?
Improved Interface Circuit for Enhancing the Power Output of a Vibration-Threshold-Triggered Piezoelectric Energy Harvester
Energies
IF0

