Defending against Adversarial Images using Basis Functions Transformations
arXiv:1803.10840
Abstract
We study the effectiveness of various approaches that defend against adversarial attacks on deep networks via manipulations based on basis function representations of images. Specifically, we experiment with low-pass filtering, PCA, JPEG compression, low resolution wavelet approximation, and soft-thresholding. We evaluate these defense techniques using three types of popular attacks in black, gray and white-box settings. Our results show JPEG compression tends to outperform the other tested defenses in most of the settings considered, in addition to soft-thresholding, which performs well in specific cases, and yields a more mild decrease in accuracy on benign examples. In addition, we also mathematically derive a novel white-box attack in which the adversarial perturbation is composed only of terms corresponding a to pre-determined subset of the basis functions, of which a "low frequency attack" is a special case.
added link to GitHub repository
References in corpus (15)
- Intriguing properties of neural networks
- Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples
- Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples
- Delving into Transferable Adversarial Examples and Black-box Attacks
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- Countering Adversarial Images using Input Transformations
- Understanding Adversarial Training: Increasing Local Stability of Neural Nets through Robust Optimization
- A study of the effect of JPG compression on adversarial images
- Keeping the Bad Guys Out: Protecting and Vaccinating Deep Learning with JPEG Compression
- Adversarial Examples: Attacks and Defenses for Deep Learning
- Parseval Networks: Improving Robustness to Adversarial Examples
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- Early Methods for Detecting Adversarial Images
- Defense against Universal Adversarial Perturbations
- Adversarial Examples Detection in Deep Networks with Convolutional Filter Statistics
Cited by in corpus (15)
- Adversarial Attacks and Defences: A Survey
- Motivating the Rules of the Game for Adversarial Example Research
- Adversarial Examples on Graph Data: Deep Insights into Attack and Defense
- Adversarial Examples - A Complete Characterisation of the Phenomenon
- A Survey of Black-Box Adversarial Attacks on Computer Vision Models
- Feature Distillation: DNN-Oriented JPEG Compression Against Adversarial Examples
- PAC-learning in the presence of evasion adversaries
- How Robust are Discriminatively Trained Zero-Shot Learning Models?
- Adversarial Examples on Object Recognition: A Comprehensive Survey
- On the Limitations of Denoising Strategies as Adversarial Defenses
- Adversarial Defense of Image Classification Using a Variational Auto-Encoder
- FBI: Fingerprinting models with Benign Inputs
- Defense-guided Transferable Adversarial Attacks
- Defenses Against Multi-Sticker Physical Domain Attacks on Classifiers
- Investigating Image Applications Based on Spatial-Frequency Transform and Deep Learning Techniques