Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
97 tokens/sec
GPT-4o
53 tokens/sec
Gemini 2.5 Pro Pro
44 tokens/sec
o3 Pro
5 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Learning to Separate Clusters of Adversarial Representations for Robust Adversarial Detection (2012.03483v1)

Published 7 Dec 2020 in cs.LG, cs.AI, and cs.CR

Abstract: Although deep neural networks have shown promising performances on various tasks, they are susceptible to incorrect predictions induced by imperceptibly small perturbations in inputs. A large number of previous works proposed to detect adversarial attacks. Yet, most of them cannot effectively detect them against adaptive whitebox attacks where an adversary has the knowledge of the model and the defense method. In this paper, we propose a new probabilistic adversarial detector motivated by a recently introduced non-robust feature. We consider the non-robust features as a common property of adversarial examples, and we deduce it is possible to find a cluster in representation space corresponding to the property. This idea leads us to probability estimate distribution of adversarial representations in a separate cluster, and leverage the distribution for a likelihood based adversarial detector.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (5)
  1. Byunggill Joe (4 papers)
  2. Jihun Hamm (28 papers)
  3. Sung Ju Hwang (178 papers)
  4. Sooel Son (6 papers)
  5. Insik Shin (9 papers)

Summary

We haven't generated a summary for this paper yet.