Non-Negative Networks Against Adversarial Attacks
arXiv:1806.06108
Abstract
Adversarial attacks against neural networks are a problem of considerable importance, for which effective defenses are not yet readily available. We make progress toward this problem by showing that non-negative weight constraints can be used to improve resistance in specific scenarios. In particular, we show that they can provide an effective defense for binary classification problems with asymmetric cost, such as malware or spam detection. We also show the potential for non-negativity to be helpful to non-binary problems by applying it to image classification.
References in corpus (5)
- Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples
- Security Evaluation of Pattern Classifiers under Attack
- Adversarial Perturbations Against Deep Neural Networks for Malware Classification
- Adversarial Examples: Attacks and Defenses for Deep Learning
- Deep Neural Network Based Malware Detection Using Two Dimensional Binary Program Features
Cited by in corpus (6)
- Malware Makeover: Breaking ML-based Static Analysis by Modifying Executable Bytes
- Machine Learning (In) Security: A Stream of Problems
- A Survey of Machine Learning Methods and Challenges for Windows Malware Classification
- Binary Black-box Evasion Attacks Against Deep Learning-based Static Malware Detectors with Adversarial Byte-Level Language Model
- Adversarial Attacks, Regression, and Numerical Stability Regularization
- Feature-level Malware Obfuscation in Deep Learning