Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
110 tokens/sec
GPT-4o
56 tokens/sec
Gemini 2.5 Pro Pro
44 tokens/sec
o3 Pro
6 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Robust Classification using Robust Feature Augmentation (1905.10904v3)

Published 26 May 2019 in cs.LG and stat.ML

Abstract: Existing deep neural networks, say for image classification, have been shown to be vulnerable to adversarial images that can cause a DNN misclassification, without any perceptible change to an image. In this work, we propose shock absorbing robust features such as binarization, e.g., rounding, and group extraction, e.g., color or shape, to augment the classification pipeline, resulting in more robust classifiers. Experimentally, we show that augmenting ML models with these techniques leads to improved overall robustness on adversarial inputs as well as significant improvements in training time. On the MNIST dataset, we achieved 14x speedup in training time to obtain 90% adversarial accuracy com-pared to the state-of-the-art adversarial training method of Madry et al., as well as retained higher adversarial accuracy over a broader range of attacks. We also find robustness improvements on traffic sign classification using robust feature augmentation. Finally, we give theoretical insights for why one can expect robust feature augmentation to reduce adversarial input space

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (6)
  1. Kevin Eykholt (16 papers)
  2. Swati Gupta (34 papers)
  3. Atul Prakash (36 papers)
  4. Amir Rahmati (17 papers)
  5. Pratik Vaishnavi (7 papers)
  6. Haizhong Zheng (14 papers)
Citations (2)

Summary

We haven't generated a summary for this paper yet.