Evolving Robust Neural Architectures to Defend from Adversarial Attacks
arXiv:1906.11667
Abstract
Neural networks are prone to misclassify slightly modified input images. Recently, many defences have been proposed, but none have improved the robustness of neural networks consistently. Here, we propose to use adversarial attacks as a function evaluation to search for neural architectures that can resist such attacks automatically. Experiments on neural architecture search algorithms from the literature show that although accurate, they are not able to find robust architectures. A significant reason for this lies in their limited search space. By creating a novel neural architecture search with options for dense layers to connect with convolution layers and vice-versa as well as the addition of concatenation layers in the search, we were able to evolve an architecture that is inherently accurate on adversarial samples. Interestingly, this inherent robustness of the evolved architecture rivals state-of-the-art defences such as adversarial training while being trained only on the non-adversarial samples. Moreover, the evolved architecture makes use of some peculiar traits which might be useful for developing even more robust ones. Thus, the results here confirm that more robust architectures exist as well as opens up a new realm of feasibilities for the development and exploration of neural networks. Code available at http://bit.ly/RobustArchitectureSearch.
Pre-print of the published article in Proceedings of the Workshop on Artificial Intelligence Safety 2020, co-located with the 29th International Joint Conference on Artificial Intelligence and the 17th Pacific Rim International Conference on Artificial Intelligence (IJCAI-PRICAI 2020)
References in corpus (13)
- Neural Architecture Search with Reinforcement Learning
- AutoML: A Survey of the State-of-the-Art
- Efficient Neural Architecture Search via Parameter Sharing
- Characterizing Adversarial Subspaces Using Local Intrinsic Dimensionality
- Neural Architecture Optimization
- SMASH: One-Shot Model Architecture Search through HyperNetworks
- Adversarial Risk and the Dangers of Evaluating Against Weak Attacks
- Efficient Architecture Search by Network Transformation
- PixelDefend: Leveraging Generative Models to Understand and Defend against Adversarial Examples
- Neural Architecture Search with Bayesian Optimisation and Optimal Transport
- Hierarchical Representations for Efficient Architecture Search
- Path-Level Network Transformation for Efficient Architecture Search
- Adversarial Robustness Assessment: Why both and Attacks Are Necessary
Cited by in corpus (8)
- AutoML: A Survey of the State-of-the-Art
- A Survey on Evolutionary Neural Architecture Search
- A Comprehensive Survey on Hardware-Aware Neural Architecture Search
- Weight-Sharing Neural Architecture Search: A Battle to Shrink the Optimization Gap
- Learning Diverse-Structured Networks for Adversarial Robustness
- Anti-Bandit Neural Architecture Search for Model Defense
- Multi-objective Search of Robust Neural Architectures against Multiple Types of Adversarial Attacks
- Poisoning the Search Space in Neural Architecture Search