Adversarial Training against Location-Optimized Adversarial Patches
arXiv:2005.02313 · doi:10.1007/978-3-030-68238-5_32
Abstract
Deep neural networks have been shown to be susceptible to adversarial examples -- small, imperceptible changes constructed to cause mis-classification in otherwise highly accurate image classifiers. As a practical alternative, recent work proposed so-called adversarial patches: clearly visible, but adversarially crafted rectangular patches in images. These patches can easily be printed and applied in the physical world. While defenses against imperceptible adversarial examples have been studied extensively, robustness against adversarial patches is poorly understood. In this work, we first devise a practical approach to obtain adversarial patches while actively optimizing their location within the image. Then, we apply adversarial training on these location-optimized adversarial patches and demonstrate significantly improved robustness on CIFAR10 and GTSRB. Additionally, in contrast to adversarial training on imperceptible adversarial examples, our adversarial patch training does not reduce accuracy.
20 pages, 6 tables, 4 figures, 2 algorithms, European Conference on Computer Vision Workshops 2020
References in corpus (14)
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Theoretically Principled Trade-off between Robustness and Accuracy
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
- Fast is better than free: Revisiting adversarial training
- Spatially Transformed Adversarial Examples
- Defensive Distillation is Not Robust to Adversarial Examples
- MagNet and "Efficient Defenses Against Adversarial Attacks" are Not Robust to Adversarial Examples
- On Physical Adversarial Patches for Object Detection
- Biologically inspired protection of deep networks from adversarial attacks
- Certified Defenses for Adversarial Patches
- Exploring the Space of Black-box Attacks on Deep Neural Networks
- Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets
- The Limitations of Adversarial Training and the Blind-Spot Attack
- Enhanced Attacks on Defensively Distilled Deep Neural Networks
Cited by in corpus (6)
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and Masking
- Defending Person Detection Against Adversarial Patch Attack by using Universal Defensive Frame
- PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image Classifier
- A Real-time Defense against Website Fingerprinting Attacks
- PatchCensor: Patch Robustness Certification for Transformers via Exhaustive Testing
- Point Adversarial Self Mining: A Simple Method for Facial Expression Recognition