Divide, Denoise, and Defend against Adversarial Attacks [article]

Seyed-Mohsen Moosavi-Dezfooli, Ashish Shrivastava, Oncel Tuzel
<span title="2019-04-25">2019</span> <i > arXiv </i> &nbsp; <span class="release-stage" >pre-print</span>
Deep neural networks, although shown to be a successful class of machine learning algorithms, are known to be extremely unstable to adversarial perturbations. Improving the robustness of neural networks against these attacks is important, especially for security-critical applications. To defend against such attacks, we propose dividing the input image into multiple patches, denoising each patch independently, and reconstructing the image, without losing significant image content. We call our
more &raquo; ... hod D3. This proposed defense mechanism is non-differentiable which makes it non-trivial for an adversary to apply gradient-based attacks. Moreover, we do not fine-tune the network with adversarial examples, making it more robust against unknown attacks. We present an analysis of the tradeoff between accuracy and robustness against adversarial attacks. We evaluate our method under black-box, grey-box, and white-box settings. On the ImageNet dataset, our method outperforms the state-of-the-art by 19.7% under grey-box setting, and performs comparably under black-box setting. For the white-box setting, the proposed method achieves 34.4% accuracy compared to the 0% reported in the recent works.
<span class="external-identifiers"> <a target="_blank" rel="external noopener" href="https://arxiv.org/abs/1802.06806v2">arXiv:1802.06806v2</a> <a target="_blank" rel="external noopener" href="https://fatcat.wiki/release/kow6q2mphjck5p3tltyf6c2r7a">fatcat:kow6q2mphjck5p3tltyf6c2r7a</a> </span>
<a target="_blank" rel="noopener" href="https://web.archive.org/web/20200827035954/https://arxiv.org/pdf/1802.06806v2.pdf" title="fulltext PDF download" data-goatcounter-click="serp-fulltext" data-goatcounter-title="serp-fulltext"> <button class="ui simple right pointing dropdown compact black labeled icon button serp-button"> <i class="icon ia-icon"></i> Web Archive [PDF] <div class="menu fulltext-thumbnail"> <img src="https://blobs.fatcat.wiki/thumbnail/pdf/4f/63/4f63e47febb2672d637c5969a46d42a14abb5f75.180px.jpg" alt="fulltext thumbnail" loading="lazy"> </div> </button> </a> <a target="_blank" rel="external noopener" href="https://arxiv.org/abs/1802.06806v2" title="arxiv.org access"> <button class="ui compact blue labeled icon button serp-button"> <i class="file alternate outline icon"></i> arxiv.org </button> </a>