Countering Adversarial Images using Input Transformations
arXiv:1711.00117
Abstract
This paper investigates strategies that defend against adversarial-example attacks on image-classification systems by transforming the inputs before feeding them to the system. Specifically, we study applying image transformations such as bit-depth reduction, JPEG compression, total variance minimization, and image quilting before feeding the image to a convolutional network classifier. Our experiments on ImageNet show that total variance minimization and image quilting are very effective defenses in practice, in particular, when the network is trained on transformed images. The strength of those defenses lies in their non-differentiable nature and their inherent randomness, which makes it difficult for an adversary to circumvent the defenses. Our best defense eliminates 60% of strong gray-box and 90% of strong black-box attacks by a variety of major attack methods
12 pages, 6 figures, submitted to ICLR 2018
References in corpus (4)
Cited by in corpus (64)
- Fast is better than free: Revisiting adversarial training
- On the Convergence and Robustness of Adversarial Training
- advertorch v0.1: An Adversarial Robustness Toolbox based on PyTorch
- Adversarial Examples Are a Natural Consequence of Test Error in Noise
- Adversarial Examples that Fool Detectors
- Improving the Transferability of Adversarial Examples with Resized-Diverse-Inputs, Diversity-Ensemble and Region Fitting
- The Limitations of Adversarial Training and the Blind-Spot Attack
- ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation
- Towards Evaluating the Robustness of Deep Diagnostic Models by Adversarial Attack
- Overfitting in adversarially robust deep learning
- Reflection Backdoor: A Natural Backdoor Attack on Deep Neural Networks
- Understanding the Decision Boundary of Deep Neural Networks: An Empirical Study
- A Survey on Security Attacks and Defense Techniques for Connected and Autonomous Vehicles
- A Survey of Black-Box Adversarial Attacks on Computer Vision Models
- Enhancing the Robustness of Deep Neural Networks by Boundary Conditional GAN
- Natural and Adversarial Error Detection using Invariance to Image Transformations
- PuVAE: A Variational Autoencoder to Purify Adversarial Examples
- Enhancing Gradient-based Attacks with Symbolic Intervals
- Adversarial Examples on Object Recognition: A Comprehensive Survey
- Adversarial Feature Augmentation and Normalization for Visual Recognition
- On Certifying Non-uniform Bound against Adversarial Attacks
- Adversarial Perturbations Prevail in the Y-Channel of the YCbCr Color Space
- Fuzzy Unique Image Transformation: Defense Against Adversarial Attacks On Deep COVID-19 Models
- A Person Re-identification Data Augmentation Method with Adversarial Defense Effect
- AdvKnn: Adversarial Attacks On K-Nearest Neighbor Classifiers With Approximate Gradients
- Over-parameterized Adversarial Training: An Analysis Overcoming the Curse of Dimensionality
- Better the Devil you Know: An Analysis of Evasion Attacks using Out-of-Distribution Adversarial Examples
- Attacking and Defending Machine Learning Applications of Public Cloud
- On Adversarial Robustness of 3D Point Cloud Classification under Adaptive Attacks
- Dealing with Adversarial Player Strategies in the Neural Network Game iNNk through Ensemble Learning
- Towards Characterizing Adversarial Defects of Deep Learning Software from the Lens of Uncertainty
- QAIR: Practical Query-efficient Black-Box Attacks for Image Retrieval
- Purifying Adversarial Perturbation with Adversarially Trained Auto-encoders
- Ptolemy: Architecture Support for Robust Deep Learning
- Ensemble Defense with Data Diversity: Weak Correlation Implies Strong Robustness
- Understanding the Error in Evaluating Adversarial Robustness
- Attack as Defense: Characterizing Adversarial Examples using Robustness
- Adversarial Robustness for Unsupervised Domain Adaptation
- AdvFilter: Predictive Perturbation-aware Filtering against Adversarial Attack via Multi-domain Learning
- Adversarial collision attacks on image hashing functions
- The Vulnerability of the Neural Networks Against Adversarial Examples in Deep Learning Algorithms
- An Empirical Study of DNNs Robustification Inefficacy in Protecting Visual Recommenders
- ADA: A Game-Theoretic Perspective on Data Augmentation for Object Detection
- Augmenting Model Robustness with Transformation-Invariant Attacks
- Local Competition and Uncertainty for Adversarial Robustness in Deep Learning
- Can audio-visual integration strengthen robustness under multimodal attacks?
- Non-Determinism in Neural Networks for Adversarial Robustness
- Robust Single-step Adversarial Training with Regularizer
- Local Competition and Stochasticity for Adversarial Robustness in Deep Learning
- A Useful Taxonomy for Adversarial Robustness of Neural Networks
- Achieving Adversarial Robustness Requires An Active Teacher
- Learning to Separate Clusters of Adversarial Representations for Robust Adversarial Detection
- Robust Text CAPTCHAs Using Adversarial Examples
- Likelihood Landscapes: A Unifying Principle Behind Many Adversarial Defenses
- Defense-friendly Images in Adversarial Attacks: Dataset and Metrics for Perturbation Difficulty
- Defenses Against Multi-Sticker Physical Domain Attacks on Classifiers
- Sparse Coding Frontend for Robust Neural Networks
- Delving into Deep Image Prior for Adversarial Defense: A Novel Reconstruction-based Defense Framework
- AID-Purifier: A Light Auxiliary Network for Boosting Adversarial Defense
- On Intrinsic Dataset Properties for Adversarial Machine Learning
- Orthogonal Deep Models As Defense Against Black-Box Attacks
- Improving Resistance to Adversarial Deformations by Regularizing Gradients
- Defending Against Adversarial Attacks Using Random Forests
- A Neuro-Inspired Autoencoding Defense Against Adversarial Perturbations