We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.LG

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Machine Learning

Title: Adversarial Defense via Data Dependent Activation Function and Total Variation Minimization

Abstract: We improve the robustness of Deep Neural Net (DNN) to adversarial attacks by using an interpolating function as the output activation. This data-dependent activation remarkably improves both the generalization and robustness of DNN. In the CIFAR10 benchmark, we raise the robust accuracy of the adversarially trained ResNet20 from $\sim 46\%$ to $\sim 69\%$ under the state-of-the-art Iterative Fast Gradient Sign Method (IFGSM) based adversarial attack. When we combine this data-dependent activation with total variation minimization on adversarial images and training data augmentation, we achieve an improvement in robust accuracy by 38.9$\%$ for ResNet56 under the strongest IFGSM attack. Furthermore, We provide an intuitive explanation of our defense by analyzing the geometry of the feature space.
Comments: 17 pages, 6 figures
Subjects: Machine Learning (cs.LG); Numerical Analysis (math.NA); Machine Learning (stat.ML)
MSC classes: 68Pxx
Journal reference: Inverse Problems and Imaging, 2020
Cite as: arXiv:1809.08516 [cs.LG]
  (or arXiv:1809.08516v3 [cs.LG] for this version)

Submission history

From: Bao Wang [view email]
[v1] Sun, 23 Sep 2018 02:33:31 GMT (2467kb,D)
[v2] Tue, 27 Nov 2018 17:54:21 GMT (1811kb,D)
[v3] Wed, 29 Apr 2020 07:05:16 GMT (1813kb,D)

Link back to: arXiv, form interface, contact.