Cascade Adversarial Machine Learning Regularized with a Unified Embedding
arXiv:1708.02582
Abstract
Injecting adversarial examples during training, known as adversarial training, can improve robustness against one-step attacks, but not for unknown iterative attacks. To address this challenge, we first show iteratively generated adversarial images easily transfer between networks trained with the same strategy. Inspired by this observation, we propose cascade adversarial training, which transfers the knowledge of the end results of adversarial training. We train a network from scratch by injecting iteratively generated adversarial images crafted from already defended networks in addition to one-step adversarial images from the network being trained. We also propose to utilize embedding space for both classification and low-level (pixel-level) similarity learning to ignore unknown pixel level perturbation. During training, we inject adversarial images without replacing their corresponding clean images and penalize the distance between the two embeddings (clean and adversarial). Experimental results show that cascade adversarial training together with our proposed low-level similarity learning efficiently enhances the robustness against iterative attacks, but at the expense of decreased robustness against one-step attacks. We show that combining those two techniques can also improve robustness under the worst case black box attack scenario.
16 pages, 9 figures, International Conference on Learning Representations (ICLR) 2018
References in corpus (1)
Cited by in corpus (16)
- Theoretically Principled Trade-off between Robustness and Accuracy
- Adversarial Machine Learning in Image Classification: A Survey Towards the Defender's Perspective
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- Improving Adversarial Robustness of Ensembles with Diversity Training
- Security and Privacy Issues in Deep Learning
- Adversarial Defense Framework for Graph Neural Network
- Improving adversarial robustness of deep neural networks by using semantic information
- Enhancing the Robustness of Deep Neural Networks by Boundary Conditional GAN
- Gradient Band-based Adversarial Training for Generalized Attack Immunity of A3C Path Finding
- Attacking and Defending Machine Learning Applications of Public Cloud
- Artificial Immune System of Secure Face Recognition Against Adversarial Attacks
- Feature Prioritization and Regularization Improve Standard Accuracy and Adversarial Robustness
- Optimal Transport Classifier: Defending Against Adversarial Attacks by Regularized Deep Embedding
- Adversarial Defense Through Network Profiling Based Path Extraction
- Mitigating Gradient-based Adversarial Attacks via Denoising and Compression
- The art of defense: letting networks fool the attacker