Extending Defensive Distillation
arXiv:1705.05264
Abstract
Machine learning is vulnerable to adversarial examples: inputs carefully modified to force misclassification. Designing defenses against such inputs remains largely an open problem. In this work, we revisit defensive distillation---which is one of the mechanisms proposed to mitigate adversarial examples---to address its limitations. We view our results not only as an effective way of addressing some of the recently discovered attacks but also as reinforcing the importance of improved training techniques.
References in corpus (3)
Cited by in corpus (5)
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- APE-GAN: Adversarial Perturbation Elimination with GAN
- Detecting Adversarial Attacks on Neural Network Policies with Visual Foresight
- Enhancing Gradient-based Attacks with Symbolic Intervals
- Latent Adversarial Defence with Boundary-guided Generation