Reinforcing the Robustness of a Deep Neural Network to Adversarial Examples by Using Color Quantization of Training Image Data
Reinforcing the Robustness of a Deep Neural Network to Adversarial Examples by Using Color Quantization of Training Image Data
复制标题
DOI:
10.1109/icip.2019.8802996
复制
发表时间:
2019-09
期刊:
影响因子:
--
通讯作者:
Shuntaro Miyazato;Xueting Wang;T. Yamasaki;K. Aizawa
中科院分区:
文献类型:
--
作者:
Shuntaro Miyazato;Xueting Wang;T. Yamasaki;K. Aizawa
Recent works have shown the vulnerability of deep convolutional neural network (DCNN) to adversarial examples with malicious perturbations. In particular, Black-Box attacks without information of parameter and architectures of the target models are feared as realistic threats. To address this problem, we propose a method using an ensemble of models trained by color-quantized data with loss maximization. Color-quantization can allow the trained models to focus on learning conspicuous spatial features to enhance the robustness of DCNNs to adversarial examples. The proposed method can be adapted to Black-Box attacks with no need of particular attack algorithm for the defense. The results of our experiments validated the effectiveness for preventing decrease in the test accuracy with adversarial perturbation.