Foveation-based Mechanisms Alleviate Adversarial Examples
arXiv:1511.06292
Abstract
We show that adversarial examples, i.e., the visually imperceptible perturbations that result in Convolutional Neural Networks (CNNs) fail, can be alleviated with a mechanism based on foveations---applying the CNN in different image regions. To see this, first, we report results in ImageNet that lead to a revision of the hypothesis that adversarial perturbations are a consequence of CNNs acting as a linear classifier: CNNs act locally linearly to changes in the image regions with objects recognized by the CNN, and in other regions the CNN may act non-linearly. Then, we corroborate that when the neural responses are linear, applying the foveation mechanism to the adversarial example tends to significantly reduce the effect of the perturbation. This is because, hypothetically, the CNNs for ImageNet are robust to changes of scale and translation of the object produced by the foveation, but this property does not generalize to transformations of the perturbation. As a result, the accuracy after a foveation is almost the same as the accuracy of the CNN without the adversarial perturbation, even if the adversarial perturbation is calculated taking into account a foveation.
References in corpus (2)
Cited by in corpus (47)
- Ensemble Adversarial Training: Attacks and Defenses
- Synthesizing Robust Adversarial Examples
- Keeping the Bad Guys Out: Protecting and Vaccinating Deep Learning with JPEG Compression
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- Motivating the Rules of the Game for Adversarial Example Research
- Early Methods for Detecting Adversarial Images
- Robustness of classifiers: from adversarial to random noise
- Characterizing Audio Adversarial Examples Using Temporal Dependency
- Smooth Adversarial Training
- Adversarial Examples for Semantic Segmentation and Object Detection
- Towards an integration of deep learning and neuroscience
- Are Accuracy and Robustness Correlated?
- Adversarial Examples - A Complete Characterisation of the Phenomenon
- Saccader: Improving Accuracy of Hard Attention Models for Vision
- Towards a Robust and Trustworthy Machine Learning System Development: An Engineering Perspective
- Defense against Universal Adversarial Perturbations
- Morphence: Moving Target Defense Against Adversarial Examples
- Emergent Properties of Foveated Perceptual Systems
- Fooling a Real Car with Adversarial Traffic Signs
- Assessing Threat of Adversarial Examples on Deep Neural Networks
- Improving adversarial robustness of deep neural networks by using semantic information
- Adversarial Examples Detection in Deep Networks with Convolutional Filter Statistics
- Adversarial Defense via Data Dependent Activation Function and Total Variation Minimization
- Enhancing Cross-task Transferability of Adversarial Examples with Dispersion Reduction
- Adversarial Examples on Object Recognition: A Comprehensive Survey
- Use the Spear as a Shield: A Novel Adversarial Example based Privacy-Preserving Technique against Membership Inference Attacks
- ATHENA: A Framework based on Diverse Weak Defenses for Building Adversarial Defense
- Unsupervised Hard Example Mining from Videos for Improved Object Detection
- Enhancing Cross-task Black-Box Transferability of Adversarial Examples with Dispersion Reduction
- Generative Dynamic Patch Attack
- Cooling-Shrinking Attack: Blinding the Tracker with Imperceptible Noises
- Built-in Vulnerabilities to Imperceptible Adversarial Perturbations
- Defense-VAE: A Fast and Accurate Defense against Adversarial Attacks
- Attacking CNN-based anti-spoofing face authentication in the physical domain
- CUDA-Optimized real-time rendering of a Foveated Visual System
- Recurrent Attention Model with Log-Polar Mapping is Robust against Adversarial Attacks
- Implicit Generative Modeling of Random Noise during Training for Adversarial Robustness
- Do Deep Neural Networks Suffer from Crowding?
- Regularized Ensembles and Transferability in Adversarial Learning
- FoveaTer: Foveated Transformer for Image Classification
- Unifying Bilateral Filtering and Adversarial Training for Robust Neural Networks
- The Foes of Neural Network's Data Efficiency Among Unnecessary Input Dimensions
- Fashion-Guided Adversarial Attack on Person Segmentation
- Landmark Breaker: Obstructing DeepFake By Disturbing Landmark Extraction
- Messing Up 3D Virtual Environments: Transferable Adversarial 3D Objects
- Adversarial Ranking Attack and Defense
- Weighted Average Precision: Adversarial Example Detection in the Visual Perception of Autonomous Vehicles