Robust Convolutional Neural Networks under Adversarial Noise
arXiv:1511.06306
Abstract
Recent studies have shown that Convolutional Neural Networks (CNNs) are vulnerable to a small perturbation of input called "adversarial examples". In this work, we propose a new feedforward CNN that improves robustness in the presence of adversarial noise. Our model uses stochastic additive noise added to the input image and to the CNN models. The proposed model operates in conjunction with a CNN trained with either standard or adversarial objective function. In particular, convolution, max-pooling, and ReLU layers are modified to benefit from the noise model. Our feedforward model is parameterized by only a mean and variance per pixel which simplifies computations and makes our method scalable to a deep architecture. From CIFAR-10 and ImageNet test, the proposed model outperforms other methods and the improvement is more evident for difficult classification tasks or stronger adversarial noise.
8 pages
References in corpus (7)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- Improving neural networks by preventing co-adaptation of feature detectors
- One weird trick for parallelizing convolutional neural networks
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- Stochastic Pooling for Regularization of Deep Convolutional Neural Networks
- Learning with a Strong Adversary
- Techniques for Learning Binary Stochastic Feedforward Neural Networks
Cited by in corpus (21)
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Regularized Deep Networks in Intelligent Transportation Systems: A Taxonomy and a Case Study
- A General Framework for Uncertainty Estimation in Deep Learning
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- An Improved Evaluation Framework for Generative Adversarial Networks
- A Theoretical Framework for Robustness of (Deep) Classifiers against Adversarial Examples
- Single Shot MC Dropout Approximation
- HyperNetworks with statistical filtering for defending adversarial examples
- The redshift evolution of the S0 fraction for in COSMOS
- Benchmarking the Robustness of Instance Segmentation Models
- A morphological segmentation approach to determining bar lengths
- Style transfer-based image synthesis as an efficient regularization technique in deep learning
- Weight Map Layer for Noise and Adversarial Attack Robustness
- Text Data Augmentation: Towards better detection of spear-phishing emails
- Detecting Adversarial Perturbations with Saliency
- Mitigation of Adversarial Attacks through Embedded Feature Selection
- An Empirical Investigation of Randomized Defenses against Adversarial Attacks
- Identifying and Exploiting Structures for Reliable Deep Learning
- Attribution of Gradient Based Adversarial Attacks for Reverse Engineering of Deceptions
- An Introduction to Robust Graph Convolutional Networks
- Enhance Convolutional Neural Networks with Noise Incentive Block