We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.LG

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Machine Learning

Title: Adversarial Detection by Approximation of Ensemble Boundary

Authors: T. Windeatt
Abstract: A new method of detecting adversarial attacks is proposed for an ensemble of Deep Neural Networks (DNNs) solving two-class pattern recognition problems. The ensemble is combined using Walsh coefficients which are capable of approximating Boolean functions and thereby controlling the complexity of the ensemble decision boundary. The hypothesis in this paper is that decision boundaries with high curvature allow adversarial perturbations to be found, but change the curvature of the decision boundary, which is then approximated in a different way by Walsh coefficients compared to the clean images. By observing the difference in Walsh coefficient approximation between clean and adversarial images, it is shown experimentally that transferability of attack may be used for detection. Furthermore, approximating the decision boundary may aid in understanding the learning and transferability properties of DNNs. While the experiments here use images, the proposed approach of modelling two-class ensemble decision boundaries could in principle be applied to any application area. Code for approximating Boolean functions using Walsh coefficients: this https URL
Comments: 17 pages, 5 figures, 5 tables
Subjects: Machine Learning (cs.LG); Artificial Intelligence (cs.AI); Cryptography and Security (cs.CR); Computer Vision and Pattern Recognition (cs.CV)
Cite as: arXiv:2211.10227 [cs.LG]
  (or arXiv:2211.10227v4 [cs.LG] for this version)

Submission history

From: Terry Windeatt [view email]
[v1] Fri, 18 Nov 2022 13:26:57 GMT (920kb)
[v2] Mon, 28 Nov 2022 16:39:49 GMT (667kb)
[v3] Tue, 13 Dec 2022 16:03:26 GMT (617kb)
[v4] Wed, 24 Jan 2024 11:38:25 GMT (414kb,D)

Link back to: arXiv, form interface, contact.