Hitting Depth : Investigating Robustness to Adversarial Examples in Deep Convolutional Neural Networks
Hitting Depth : Investigating Robustness to Adversarial Examples in Deep Convolutional Neural Networks
复制标题
命中深度:研究深度卷积神经网络中对抗性示例的鲁棒性
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
C. Billovits
中科院分区:
文献类型:
--
作者:
C. Billovits
Machine learning models, including Convolutional Neural Networks (CNN) are susceptible to adversarial examples input images that have been perturbed to deliberately fool a model into an incorrect, high-confidence prediction without a visually perceptible change. Previous work shows that high-dimensional linearities cause these adversarial pockets of space. We first validate assumptions about the generalization of gradient-based and pattern-based adversarial examples using VGGNet. We show a process for visualizing and identifying changes in activations between adversarial images and their regular counterparts. Finally, we leverage information from these two approaches in a novel Bayesian framework to increase l2 robustness to adversarial examples. Using this framework, we successfully improve the prediction accuracy on adversarial examples.