Ensemble Methods as a Defense to Adversarial Perturbations Against Deep Neural Networks
arXiv:1709.03423
Abstract
Deep learning has become the state of the art approach in many machine learning problems such as classification. It has recently been shown that deep learning is highly vulnerable to adversarial perturbations. Taking the camera systems of self-driving cars as an example, small adversarial perturbations can cause the system to make errors in important tasks, such as classifying traffic signs or detecting pedestrians. Hence, in order to use deep learning without safety concerns a proper defense strategy is required. We propose to use ensemble methods as a defense strategy against adversarial perturbations. We find that an attack leading one model to misclassify does not imply the same for other networks performing the same task. This makes ensemble methods an attractive defense strategy against adversarial attacks. We empirically show for the MNIST and the CIFAR-10 data sets that ensemble methods not only improve the accuracy of neural networks on test data but also increase their robustness against adversarial perturbations.
10 pages, 2 figures, 4 tables
References in corpus (3)
Cited by in corpus (30)
- CANet: An Unsupervised Intrusion Detection System for High Dimensional CAN Bus Data
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- Adversarial Machine Learning in Image Classification: A Survey Towards the Defender's Perspective
- Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples
- Fixing Data Augmentation to Improve Adversarial Robustness
- Improving Adversarial Robustness of Ensembles with Diversity Training
- Smooth Adversarial Training
- The Pitfalls of Simplicity Bias in Neural Networks
- Shield: Fast, Practical Defense and Vaccination for Deep Learning using JPEG Compression
- BERT Loses Patience: Fast and Robust Inference with Early Exit
- Towards Robust Neural Networks via Random Self-ensemble
- Defense Methods Against Adversarial Examples for Recurrent Neural Networks
- Triple Wins: Boosting Accuracy, Robustness and Efficiency Together by Enabling Input-Adaptive Inference
- Adversarial Robustness: From Self-Supervised Pre-Training to Fine-Tuning
- Tensor Normalization and Full Distribution Training
- ResNets Ensemble via the Feynman-Kac Formalism to Improve Natural and Robust Accuracies
- Robustifying Models Against Adversarial Attacks by Langevin Dynamics
- Security and Privacy for Artificial Intelligence: Opportunities and Challenges
- EMPIR: Ensembles of Mixed Precision Deep Networks for Increased Robustness against Adversarial Attacks
- Deep Ensembling with No Overhead for either Training or Testing: The All-Round Blessings of Dynamic Sparsity
- Voting based ensemble improves robustness of defensive models
- Deep Neural Network Ensembles against Deception: Ensemble Diversity, Accuracy and Robustness
- Enhancing Certified Robustness via Smoothed Weighted Ensembling
- -ML: Mitigating Adversarial Examples via Ensembles of Topologically Manipulated Classifiers
- Ensemble Defense with Data Diversity: Weak Correlation Implies Strong Robustness
- Omni: Automated Ensemble with Unexpected Models against Adversarial Evasion Attack
- Resilience from Diversity: Population-based approach to harden models against adversarial attacks
- Are You Tampering With My Data?
- MadNet: Using a MAD Optimization for Defending Against Adversarial Attacks
- Adversarial Training with Stochastic Weight Average