arrow
Return

Implicit adversarial data augmentation and robustness with Noise-based Learning

delete2021-09-01
delete12
delete
OA
AI
P
Priyadarshini Panda *
K
Kaushik Roy
DOI:10.1016/j.neunet.2021.04.008delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
We introduce a Noise-based Learning (NoL) approach for training neural networks that are intrinsically robust to adversarial attacks. We find that the learning of random noise introduced with the input with the same loss function used during posterior maximization, improves a model's adversarial resistance. We show that the learnt noise performs implicit adversarial data augmentation boosting a model's adversary generalization capability. We evaluate our approach's efficacy and provide a simplistic visualization tool for understanding adversarial data, using Principal Component Analysis. We conduct comprehensive experiments on prevailing benchmarks such as MNIST, CIFAR10, CIFAR100, Tiny ImageNet and show that our approach performs remarkably well against a wide range of attacks. Furthermore, combining NoL with state-of-the-art defense mechanisms, such as adversarial training, consistently outperforms prior techniques in both white-box and black-box attacks. (C) 2021 Elsevier Ltd. All rights reserved.
Keywords:
Adversarial robustness
Deep learning
Principal Component Analysis
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Neural Networks cover
Neural Networks
IF:
6.3
Papers:
7.8K
Citations:
3.0W

Organization

Y
Yale University
Scholars:
6.5W
Papers: 6.0W
Citations: 10.0W
Purdue University System cover
Purdue University System
Scholars:
3.9W
Papers: 3.6W
Citations: 66