Code-Bridged Classifier (CBC): A Low or Negative Overhead Defense for Making a CNN Classifier Robust Against Adversarial Attacks

Code-Bridged Classifier (CBC): A Low or Negative Overhead Defense for Making a CNN Classifier Robust Against Adversarial Attacks
复制标题

DOI:
10.1109/isqed48828.2020.9136987
复制
发表时间:
2020-01
期刊:
2020 21st International Symposium on Quality Electronic Design (ISQED)
影响因子:
--
通讯作者:
F. Behnia;Ali Mirzaeian;M. Sabokrou;S. Manoj;T. Mohsenin;Khaled N. Khasawneh;Liang Zhao;H. Homayoun;Avesta Sasan
F. Behnia;Ali Mirzaeian;M. Sabokrou;S. Manoj;T. Mohsenin;Khaled N. Khasawneh;Liang Zhao;H. Homayoun;Avesta Sasan
中科院分区:
其他
文献类型:
--
作者:
F. Behnia;Ali Mirzaeian;M. Sabokrou;S. Manoj;T. Mohsenin;Khaled N. Khasawneh;Liang Zhao;H. Homayoun;Avesta Sasan

文献摘要

被引文献

相似文献

在本文中,我们提出了代码桥接分类器(CBC),这是一种使卷积神经网络(CNN)在不增加甚至降低整体模型计算复杂度的情况下对对抗性攻击具有鲁棒性的框架。更具体地说,我们提出了一种堆叠式编码器 - 卷积模型,其中输入图像首先由去噪自动编码器的编码器模块进行编码,然后将得到的潜在表示(不进行解码)馈送到一个降低了复杂度的CNN中进行图像分类。我们表明,与现有技术的防御方法相比,该网络不仅对对抗样本更具鲁棒性,而且计算复杂度也显著降低。
In this paper, we propose Code-Bridged Classifier (CBC), a framework for making a Convolutional Neural Network (CNNs) robust against adversarial attacks without increasing or even by decreasing the overall models' computational complexity. More specifically, we propose a stacked encoder-convolutional model, in which the input image is first encoded by the encoder module of a denoising auto-encoder, and then the resulting latent representation (without being decoded) is fed to a reduced complexity CNN for image classification. We illustrate that this network not only is more robust to adversarial examples but also has a significantly lower computational complexity when compared to the prior art defenses.