Towards Better Accuracy and Robustness with Localized Adversarial Training
Towards Better Accuracy and Robustness with Localized Adversarial Training
复制标题
DOI:
10.1609/aaai.v33i01.330110017
复制
发表时间:
2019-07
期刊:
影响因子:
--
通讯作者:
Eitan Rothberg;Tingting Chen;Hao Ji
中科院分区:
文献类型:
--
作者:
Eitan Rothberg;Tingting Chen;Hao Ji
As technology and society grow increasingly dependent on computer vision, it becomes important to make sure that these technologies are secure. However, even today’s stateof-the-art classifiers are easily fooled by carefully manipulated images. The only solutions that have increased robustness against these manipulated images have come at the expense of accuracy on natural inputs. In this work, we propose a new training technique, localized adversarial training, that results in more accurate classification of both both natural and adversarial images by as much as 6.5% and 99.7%, respectively.