Learning with a Strong Adversary
arXiv:1511.03034
Abstract
The robustness of neural networks to intended perturbations has recently attracted significant attention. In this paper, we propose a new method, \emph{learning with a strong adversary}, that learns robust classifiers from supervised data. The proposed method takes finding adversarial examples as an intermediate step. A new and simple way of finding adversarial examples is presented and experimentally shown to be efficient. Experimental results demonstrate that resulting learning method greatly improves the robustness of the classification models produced.
References in corpus (5)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- Improving neural networks by preventing co-adaptation of feature detectors
- MXNet: A Flexible and Efficient Machine Learning Library for Heterogeneous Distributed Systems
- Apprenticeship Learning using Inverse Reinforcement Learning and Gradient Methods
- Improving Back-Propagation by Adding an Adversarial Gradient
Cited by in corpus (96)
- Towards Deep Learning Models Resistant to Adversarial Attacks
- Theoretically Principled Trade-off between Robustness and Accuracy
- Deep Variational Information Bottleneck
- Adversarial Examples: Attacks and Defenses for Deep Learning
- A General Framework for Adversarial Examples with Objectives
- Adversarial Machine Learning in Image Classification: A Survey Towards the Defender's Perspective
- How Deep Learning Sees the World: A Survey on Adversarial Attacks & Defenses
- Robustness of classifiers: from adversarial to random noise
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary Attack
- Rademacher Complexity for Adversarially Robust Generalization
- Adv-BNN: Improved Adversarial Defense through Robust Bayesian Neural Network
- Provably Minimally-Distorted Adversarial Examples
- MMA Training: Direct Input Space Margin Maximization through Adversarial Training
- Universal adversarial perturbations
- Blocking Transferability of Adversarial Examples in Black-Box Learning Systems
- Adversarial Training against Location-Optimized Adversarial Patches
- Adversarially Robust Generalization Just Requires More Unlabeled Data
- Robust Convolutional Neural Networks under Adversarial Noise
- MACER: Attack-free and Scalable Robust Training via Maximizing Certified Radius
- Partial success in closing the gap between human and machine vision
- Cascade Adversarial Machine Learning Regularized with a Unified Embedding
- Detection of Face Recognition Adversarial Attacks
- Adversarial Examples in Modern Machine Learning: A Review
- Adversarial Robustness of Deep Code Comment Generation
- Adversarial Examples - A Complete Characterisation of the Phenomenon
- Towards Robust Neural Image Compression: Adversarial Attack and Model Finetuning
- Towards Robust Neural Networks via Random Self-ensemble
- Recent Advances in Adversarial Training for Adversarial Robustness
- Confidence-Calibrated Adversarial Training: Generalizing to Unseen Attacks
- Pixle: a fast and effective black-box attack based on rearranging pixels
- The Curious Case of Adversarially Robust Models: More Data Can Help, Double Descend, or Hurt Generalization
- Adversarial Meta-Learning
- Understanding the One-Pixel Attack: Propagation Maps and Locality Analysis
- Adversarial Image Perturbation for Privacy Protection -- A Game Theory Perspective
- GraphDefense: Towards Robust Graph Convolutional Networks
- Attacks on State-of-the-Art Face Recognition using Attentional Adversarial Attack Generative Network
- Morphence: Moving Target Defense Against Adversarial Examples
- Constrained Learning with Non-Convex Losses
- Fooling a Real Car with Adversarial Traffic Signs
- Evolving Robust Neural Architectures to Defend from Adversarial Attacks
- Improving Robustness of ML Classifiers against Realizable Evasion Attacks Using Conserved Features
- Unifying Adversarial Training Algorithms with Flexible Deep Data Gradient Regularization
- RANDOM MASK: Towards Robust Convolutional Neural Networks
- On the Application of Danskin's Theorem to Derivative-Free Minimax Optimization
- A Provable Defense for Deep Residual Networks
- Adversarial Examples Detection in Deep Networks with Convolutional Filter Statistics
- FenceBox: A Platform for Defeating Adversarial Examples with Data Augmentation Techniques
- Mitigating Advanced Adversarial Attacks with More Advanced Gradient Obfuscation Techniques
- Playing the Game of Universal Adversarial Perturbations
- Large Margin Deep Networks for Classification
- Towards Security Threats of Deep Learning Systems: A Survey
- Adversarial Examples on Object Recognition: A Comprehensive Survey
- Using Non-invertible Data Transformations to Build Adversarial-Robust Neural Networks
- Adversarial Robustness Assessment: Why both and Attacks Are Necessary
- A Person Re-identification Data Augmentation Method with Adversarial Defense Effect
- Bit Error Robustness for Energy-Efficient DNN Accelerators
- Efficient Two-Step Adversarial Defense for Deep Neural Networks
- Fibres of Failure: Classifying errors in predictive processes
- SOAR: Second-Order Adversarial Regularization
- Rearchitecting Classification Frameworks For Increased Robustness
- Subset Scanning Over Neural Network Activations
- Exploring the Hyperparameter Landscape of Adversarial Robustness
- Data Quality Matters For Adversarial Training: An Empirical Study
- Machine vs Machine: Minimax-Optimal Defense Against Adversarial Examples
- Detecting Adversarial Perturbations with Saliency
- Provable robustness against all adversarial -perturbations for
- Towards Certifying L-infinity Robustness using Neural Networks with L-inf-dist Neurons
- Adversarial Robustness Study of Convolutional Neural Network for Lumbar Disk Shape Reconstruction from MR images
- ATRO: Adversarial Training with a Rejection Option
- A Review of Formal Methods applied to Machine Learning
- Defective Convolutional Networks
- Probably Approximately Correct Constrained Learning
- Perceptually Constrained Adversarial Attacks
- Beneficial Perturbations Network for Defending Adversarial Examples
- Adequacy of the Gradient-Descent Method for Classifier Evasion Attacks
- ROBY: Evaluating the Robustness of a Deep Model by its Decision Boundaries
- Vulnerability Under Adversarial Machine Learning: Bias or Variance?
- Perceptual Deep Neural Networks: Adversarial Robustness through Input Recreation
- Practical Convex Formulation of Robust One-hidden-layer Neural Network Training
- Representation Quality Of Neural Networks Links To Adversarial Attacks and Defences
- Adversarial Learning with Cost-Sensitive Classes
- Feature Importance Guided Attack: A Model Agnostic Adversarial Attack
- Learning Less Generalizable Patterns with an Asymmetrically Trained Double Classifier for Better Test-Time Adaptation
- Adaptive Gradient for Adversarial Perturbations Generation
- Adversarial Ranking Attack and Defense
- Linking average- and worst-case perturbation robustness via class selectivity and dimensionality
- Deep Minimax Probability Machine
- Can Intelligent Hyperparameter Selection Improve Resistance to Adversarial Examples?
- Simpler Certified Radius Maximization by Propagating Covariances
- TEAM: An Taylor Expansion-Based Method for Generating Adversarial Examples
- Adversarial Attacks on Deep Models for Financial Transaction Records
- Improving Adversarial Robustness for Free with Snapshot Ensemble
- Developing and Defeating Adversarial Examples
- Adversarial Training: embedding adversarial perturbations into the parameter space of a neural network to build a robust system
- Attribution of Gradient Based Adversarial Attacks for Reverse Engineering of Deceptions
- Enhancing Resilience of Deep Learning Networks by Means of Transferable Adversaries