APE-GAN: Adversarial Perturbation Elimination with GAN
arXiv:1707.05474
Abstract
Although neural networks could achieve state-of-the-art performance while recongnizing images, they often suffer a tremendous defeat from adversarial examples--inputs generated by utilizing imperceptible but intentional perturbation to clean samples from the datasets. How to defense against adversarial examples is an important problem which is well worth researching. So far, very few methods have provided a significant defense to adversarial examples. In this paper, a novel idea is proposed and an effective framework based Generative Adversarial Nets named APE-GAN is implemented to defense against the adversarial examples. The experimental results on three benchmark datasets including MNIST, CIFAR10 and ImageNet indicate that APE-GAN is effective to resist adversarial examples generated from five attacks.
14 pages
References in corpus (3)
Cited by in corpus (11)
- A Review on Generative Adversarial Networks: Algorithms, Theory, and Applications
- MagNet and "Efficient Defenses Against Adversarial Attacks" are Not Robust to Adversarial Examples
- Predify: Augmenting deep neural networks with brain-inspired predictive coding dynamics
- Generative Adversarial Networks: A Survey Towards Private and Secure Applications
- Unrestricted Adversarial Attacks on ImageNet Competition
- Minimax Defense against Gradient-based Adversarial Attacks
- A Self-supervised Approach for Adversarial Robustness
- Purifying Adversarial Perturbation with Adversarially Trained Auto-encoders
- Local Competition and Uncertainty for Adversarial Robustness in Deep Learning
- Local Competition and Stochasticity for Adversarial Robustness in Deep Learning
- Orthogonal Deep Models As Defense Against Black-Box Attacks