Towards Better Accuracy and Robustness with Localized Adversarial Training

Towards Better Accuracy and Robustness with Localized Adversarial Training
复制标题

DOI:
10.1609/aaai.v33i01.330110017
复制
发表时间:
2019-07
期刊:
--
影响因子:
--
通讯作者:
Eitan Rothberg;Tingting Chen;Hao Ji
Eitan Rothberg;Tingting Chen;Hao Ji
中科院分区:
其他
文献类型:
--
作者:
Eitan Rothberg;Tingting Chen;Hao Ji

文献摘要

被引文献

相似文献

随着技术和社会越来越依赖计算机视觉,确保这些技术的安全变得非常重要。然而,即使是今天最先进的分类器也很容易被精心操纵的图像所欺骗。唯一能够提高这些操纵图像鲁棒性的解决方案是以牺牲自然输入的准确性为代价的。在这项工作中,我们提出了一种新的训练技术,即局部对抗训练,它可以分别对自然图像和对抗图像进行6.5%和99.7%的更准确分类。
As technology and society grow increasingly dependent on computer vision, it becomes important to make sure that these technologies are secure. However, even today’s stateof-the-art classifiers are easily fooled by carefully manipulated images. The only solutions that have increased robustness against these manipulated images have come at the expense of accuracy on natural inputs. In this work, we propose a new training technique, localized adversarial training, that results in more accurate classification of both both natural and adversarial images by as much as 6.5% and 99.7%, respectively.