Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
119 tokens/sec
GPT-4o
56 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
6 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Harnessing the Vulnerability of Latent Layers in Adversarially Trained Models (1905.05186v2)

Published 13 May 2019 in cs.LG, cs.CR, cs.CV, and stat.ML

Abstract: Neural networks are vulnerable to adversarial attacks -- small visually imperceptible crafted noise which when added to the input drastically changes the output. The most effective method of defending against these adversarial attacks is to use the methodology of adversarial training. We analyze the adversarially trained robust models to study their vulnerability against adversarial attacks at the level of the latent layers. Our analysis reveals that contrary to the input layer which is robust to adversarial attack, the latent layer of these robust models are highly susceptible to adversarial perturbations of small magnitude. Leveraging this information, we introduce a new technique Latent Adversarial Training (LAT) which comprises of fine-tuning the adversarially trained models to ensure the robustness at the feature layers. We also propose Latent Attack (LA), a novel algorithm for construction of adversarial examples. LAT results in minor improvement in test accuracy and leads to a state-of-the-art adversarial accuracy against the universal first-order adversarial PGD attack which is shown for the MNIST, CIFAR-10, CIFAR-100 datasets.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (6)
  1. Mayank Singh (92 papers)
  2. Abhishek Sinha (60 papers)
  3. Nupur Kumari (18 papers)
  4. Harshitha Machiraju (7 papers)
  5. Balaji Krishnamurthy (68 papers)
  6. Vineeth N Balasubramanian (96 papers)
Citations (58)

Summary

We haven't generated a summary for this paper yet.