Feature Squeezing Mitigates and Detects Carlini/Wagner Adversarial Examples
arXiv:1705.10686
Abstract
Feature squeezing is a recently-introduced framework for mitigating and detecting adversarial examples. In previous work, we showed that it is effective against several earlier methods for generating adversarial examples. In this short note, we report on recent results showing that simple feature squeezing techniques also make deep learning models significantly more robust against the Carlini/Wagner attacks, which are the best known adversarial methods discovered to date.
Cited by in corpus (4)
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong
- Detecting Adversarial Attacks on Neural Network Policies with Visual Foresight
- Moving Target Defense for Deep Visual Sensing against Adversarial Examples