Mitigating Adversarial Effects Through Randomization
arXiv:1711.01991
Abstract
Convolutional neural networks have demonstrated high accuracy on various tasks in recent years. However, they are extremely vulnerable to adversarial examples. For example, imperceptible perturbations added to clean images can cause convolutional neural networks to fail. In this paper, we propose to utilize randomization at inference time to mitigate adversarial effects. Specifically, we use two randomization operations: random resizing, which resizes the input images to a random size, and random padding, which pads zeros around the input images in a random manner. Extensive experiments demonstrate that the proposed randomization method is very effective at defending against both single-step and iterative attacks. Our method provides the following advantages: 1) no additional training or fine-tuning, 2) very few additional computations, 3) compatible with other adversarial defense methods. By combining the proposed randomization method with an adversarially trained model, it achieves a normalized score of 0.924 (ranked No.2 among 107 defense teams) in the NIPS 2017 adversarial examples defense challenge, which is far better than using adversarial training alone with a normalized score of 0.773 (ranked No.56). The code is public available at https://github.com/cihangxie/NIPS2017_adv_challenge_defense.
To appear in ICLR 2018, code available at https://github.com/cihangxie/NIPS2017_adv_challenge_defense
References in corpus (8)
- Delving into Transferable Adversarial Examples and Black-box Attacks
- Poisoning Attacks against Support Vector Machines
- Adversarial Machine Learning at Scale
- Houdini: Fooling Deep Structured Prediction Models
- Adversarial Examples for Semantic Image Segmentation
- Visual Concepts and Compositional Voting
- Single-Shot Object Detection with Enriched Semantics
- DeepVoting: A Robust and Explainable Deep Network for Semantic Part Detection under Partial Occlusion
Cited by in corpus (67)
- Adversarial Risk and the Dangers of Evaluating Against Weak Attacks
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- Adversarial Machine Learning in Image Classification: A Survey Towards the Defender's Perspective
- Adversarial Sample Detection for Deep Neural Network through Model Mutation Testing
- Adversarial Examples Are a Natural Consequence of Test Error in Noise
- Adversarial Attack and Defense on Point Sets
- The Limitations of Adversarial Training and the Blind-Spot Attack
- Detecting Adversarial Examples by Input Transformations, Defense Perturbations, and Voting
- Evading Defenses to Transferable Adversarial Examples by Translation-Invariant Attacks
- On Robustness of Neural Ordinary Differential Equations
- Defend Deep Neural Networks Against Adversarial Examples via Fixed and Dynamic Quantized Activation Functions
- E-LPIPS: Robust Perceptual Image Similarity via Random Transformation Ensembles
- IF-Defense: 3D Adversarial Point Cloud Defense via Implicit Function based Restoration
- Defense against Adversarial Attacks in NLP via Dirichlet Neighborhood Ensemble
- Feature Distillation: DNN-Oriented JPEG Compression Against Adversarial Examples
- DUP-Net: Denoiser and Upsampler Network for 3D Adversarial Point Clouds Defense
- ATHENA: A Framework based on Diverse Weak Defenses for Building Adversarial Defense
- Enhancing Gradient-based Attacks with Symbolic Intervals
- On Certifying Non-uniform Bound against Adversarial Attacks
- Fine-grained Synthesis of Unrestricted Adversarial Examples
- Query-Efficient Black-Box Attack by Active Learning
- Denoised Internal Models: a Brain-Inspired Autoencoder against Adversarial Attacks
- Repairing Deep Neural Networks: Fix Patterns and Challenges
- Adversarial Attacks and Defenses: An Interpretation Perspective
- On the Need for Topology-Aware Generative Models for Manifold-Based Defenses
- Effects of Loss Functions And Target Representations on Adversarial Robustness
- Attacking and Defending Machine Learning Applications of Public Cloud
- Strength in Numbers: Trading-off Robustness and Computation via Adversarially-Trained Ensembles
- Temporal Shuffling for Defending Deep Action Recognition Models against Adversarial Attacks
- Distortion Agnostic Deep Watermarking
- Higher-Order Certification for Randomized Smoothing
- Optimal Transport Classifier: Defending Against Adversarial Attacks by Regularized Deep Embedding
- Towards Understanding Limitations of Pixel Discretization Against Adversarial Attacks
- Defending Pre-trained Language Models from Adversarial Word Substitutions Without Performance Sacrifice
- Ensemble Defense with Data Diversity: Weak Correlation Implies Strong Robustness
- Drawing Robust Scratch Tickets: Subnetworks with Inborn Robustness Are Found within Randomly Initialized Networks
- Exposing the Robustness and Vulnerability of Hybrid 8T-6T SRAM Memory Architectures to Adversarial Attacks in Deep Neural Networks
- RAIN: A Simple Approach for Robust and Accurate Image Classification Networks
- DiPSeN: Differentially Private Self-normalizing Neural Networks For Adversarial Robustness in Federated Learning
- Purifying Adversarial Perturbation with Adversarially Trained Auto-encoders
- A Self-supervised Approach for Adversarial Robustness
- Ptolemy: Architecture Support for Robust Deep Learning
- Attack as Defense: Characterizing Adversarial Examples using Robustness
- AdvFoolGen: Creating Persistent Troubles for Deep Classifiers
- Ensemble-in-One: Learning Ensemble within Random Gated Networks for Enhanced Adversarial Robustness
- Local Competition and Uncertainty for Adversarial Robustness in Deep Learning
- On the Robustness of Domain Adaption to Adversarial Attacks
- Robust and Information-theoretically Safe Bias Classifier against Adversarial Attacks
- Resilience from Diversity: Population-based approach to harden models against adversarial attacks
- Can audio-visual integration strengthen robustness under multimodal attacks?
- Meta Gradient Adversarial Attack
- Non-Determinism in Neural Networks for Adversarial Robustness
- The Vulnerability of the Neural Networks Against Adversarial Examples in Deep Learning Algorithms
- Local Competition and Stochasticity for Adversarial Robustness in Deep Learning
- Analysis of Random Perturbations for Robust Convolutional Neural Networks
- DetectX -- Adversarial Input Detection using Current Signatures in Memristive XBar Arrays
- An Efficient Pre-processing Method to Eliminate Adversarial Effects
- Likelihood Landscapes: A Unifying Principle Behind Many Adversarial Defenses
- Learning to Separate Clusters of Adversarial Representations for Robust Adversarial Detection
- Harnessing adversarial examples with a surprisingly simple defense
- Exploit Clues from Views: Self-Supervised and Regularized Learning for Multiview Object Recognition
- Delving into Deep Image Prior for Adversarial Defense: A Novel Reconstruction-based Defense Framework
- The Controllability of Planning, Responsibility, and Security in Automatic Driving Technology
- Universal Physical Camouflage Attacks on Object Detectors
- Towards Optimal Randomized Strategies in Adversarial Example Game
- Effectiveness of random deep feature selection for securing image manipulation detectors against adversarial examples
- Improving Resistance to Adversarial Deformations by Regularizing Gradients