Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
110 tokens/sec
GPT-4o
56 tokens/sec
Gemini 2.5 Pro Pro
44 tokens/sec
o3 Pro
6 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Denoising and Verification Cross-Layer Ensemble Against Black-box Adversarial Attacks (1908.07667v2)

Published 21 Aug 2019 in cs.LG, cs.CR, and stat.ML

Abstract: Deep neural networks (DNNs) have demonstrated impressive performance on many challenging machine learning tasks. However, DNNs are vulnerable to adversarial inputs generated by adding maliciously crafted perturbations to the benign inputs. As a growing number of attacks have been reported to generate adversarial inputs of varying sophistication, the defense-attack arms race has been accelerated. In this paper, we present MODEF, a cross-layer model diversity ensemble framework. MODEF intelligently combines unsupervised model denoising ensemble with supervised model verification ensemble by quantifying model diversity, aiming to boost the robustness of the target model against adversarial examples. Evaluated using eleven representative attacks on popular benchmark datasets, we show that MODEF achieves remarkable defense success rates, compared with existing defense methods, and provides a superior capability of repairing adversarial inputs and making correct predictions with high accuracy in the presence of black-box attacks.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (4)
  1. Ka-Ho Chow (31 papers)
  2. Wenqi Wei (55 papers)
  3. Yanzhao Wu (38 papers)
  4. Ling Liu (132 papers)
Citations (15)

Summary

We haven't generated a summary for this paper yet.