MagNet and "Efficient Defenses Against Adversarial Attacks" are Not Robust to Adversarial Examples
arXiv:1711.08478
Abstract
MagNet and "Efficient Defenses..." were recently proposed as a defense to adversarial examples. We find that we can construct adversarial examples that defeat these defenses with only a slight increase in distortion.
References in corpus (1)
Cited by in corpus (29)
- On Evaluating Adversarial Robustness
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks
- Adversarial Examples in Modern Machine Learning: A Review
- Understanding the One-Pixel Attack: Propagation Maps and Locality Analysis
- Mitigating Advanced Adversarial Attacks with More Advanced Gradient Obfuscation Techniques
- Adversarial Examples on Object Recognition: A Comprehensive Survey
- Enhancing Gradient-based Attacks with Symbolic Intervals
- Enhancing Certifiable Robustness via a Deep Model Ensemble
- Regula Sub-rosa: Latent Backdoor Attacks on Deep Neural Networks
- Better the Devil you Know: An Analysis of Evasion Attacks using Out-of-Distribution Adversarial Examples
- Improving Global Adversarial Robustness Generalization With Adversarially Trained GAN
- Robustness Certificates Against Adversarial Examples for ReLU Networks
- Adversarial Robustness in Deep Learning: Attacks on Fragile Neurons
- Bandlimiting Neural Networks Against Adversarial Attacks
- Purifying Adversarial Perturbation with Adversarially Trained Auto-encoders
- Adversarial Defense Through Network Profiling Based Path Extraction
- Minimax Defense against Gradient-based Adversarial Attacks
- AuxBlocks: Defense Adversarial Example via Auxiliary Blocks
- Detecting Adversarial Patches with Class Conditional Reconstruction Networks
- Attack as Defense: Characterizing Adversarial Examples using Robustness
- A Computationally Efficient Method for Defending Adversarial Deep Learning Attacks
- Can the state of relevant neurons in a deep neural networks serve as indicators for detecting adversarial attacks?
- "What's in the box?!": Deflecting Adversarial Attacks by Randomly Deploying Adversarially-Disjoint Models
- Who is Responsible for Adversarial Defense?
- TEAM: We Need More Powerful Adversarial Examples for DNNs
- Delving into the pixels of adversarial samples
- Attack to Fool and Explain Deep Networks
- Target Training Does Adversarial Training Without Adversarial Samples
- Tricking Adversarial Attacks To Fail