A Neuro-Inspired Autoencoding Defense Against Adversarial Attacks
A Neuro-Inspired Autoencoding Defense Against Adversarial Attacks
复制标题
DOI:
10.1109/icip42928.2021.9506184
复制
发表时间:
2021-09
期刊:
影响因子:
--
通讯作者:
Can Bakiskan;Metehan Cekic;Ahmet Dundar Sezer;Upamanyu Madhow
中科院分区:
文献类型:
--
作者:
Can Bakiskan;Metehan Cekic;Ahmet Dundar Sezer;Upamanyu Madhow
Deep Neural Networks (DNNs) are vulnerable to adversarial attacks: carefully constructed perturbations to an image can seriously impair classification accuracy, while being imperceptible to humans. The most effective current defense is to train the network using adversarially perturbed examples. In this paper, we investigate a radically different, neuro-inspired defense mechanism, aiming to reject adversarial perturbations before they reach a classifier DNN, using an encoder with characteristics commonly observed in biological vision, followed by a decoder restoring image dimensions that can be cascaded with standard CNN architectures. Unlike adversarial training, all training is based on clean images. Our experiments on the CFAR-10 and a subset of Imagenet datasets show performance competitive with state-of-the-art adversarial training, and point to the promise of bottom-up neuro-inspired techniques for the design of robust neural networks.