Adversarial defense via the data-dependent activation, total variation minimization, and adversarial training

Adversarial defense via the data-dependent activation, total variation minimization, and adversarial training
复制标题

DOI:
10.3934/ipi.2020046
复制
发表时间:
2021
影响因子:
1.3
通讯作者:
Bao Wang;A. Lin;Penghang Yin;Wei Zhu;A. Bertozzi;S. Osher
Bao Wang;A. Lin;Penghang Yin;Wei Zhu;A. Bertozzi;S. Osher
中科院分区:
数学4区
文献类型:
--
作者:
Bao Wang;A. Lin;Penghang Yin;Wei Zhu;A. Bertozzi;S. Osher

文献摘要

相似文献

We improve the robustness of Deep Neural Net (DNN) to adversarial attacks by using an interpolating function as the output activation. This data-dependent activation remarkably improves both the generalization and robustness of DNN. In the CIFAR10 benchmark, we raise the robust accuracy of the adversarially trained ResNet20 from \begin{document}$ \sim 46\% $\end{document} to \begin{document}$ \sim 69\% $\end{document} under the state-of-the-art Iterative Fast Gradient Sign Method (IFGSM) based adversarial attack. When we combine this data-dependent activation with total variation minimization on adversarial images and training data augmentation, we achieve an improvement in robust accuracy by 38.9 \begin{document}$ \% $\end{document} for ResNet56 under the strongest IFGSM attack. Furthermore, We provide an intuitive explanation of our defense by analyzing the geometry of the feature space.
We improve the robustness of Deep Neural Net (DNN) to adversarial attacks by using an interpolating function as the output activation. This data-dependent activation remarkably improves both the generalization and robustness of DNN. In the CIFAR10 benchmark, we raise the robust accuracy of the adversarially trained ResNet20 from \begin{document}$ \sim 46\% $\end{document} to \begin{document}$ \sim 69\% $\end{document} under the state-of-the-art Iterative Fast Gradient Sign Method (IFGSM) based adversarial attack. When we combine this data-dependent activation with total variation minimization on adversarial images and training data augmentation, we achieve an improvement in robust accuracy by 38.9 \begin{document}$ \% $\end{document} for ResNet56 under the strongest IFGSM attack. Furthermore, We provide an intuitive explanation of our defense by analyzing the geometry of the feature space.