Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Adversarial Defense via Data Dependent Activation Function and Total Variation Minimization

About

We improve the robustness of Deep Neural Net (DNN) to adversarial attacks by using an interpolating function as the output activation. This data-dependent activation remarkably improves both the generalization and robustness of DNN. In the CIFAR10 benchmark, we raise the robust accuracy of the adversarially trained ResNet20 from $\sim 46\%$ to $\sim 69\%$ under the state-of-the-art Iterative Fast Gradient Sign Method (IFGSM) based adversarial attack. When we combine this data-dependent activation with total variation minimization on adversarial images and training data augmentation, we achieve an improvement in robust accuracy by 38.9$\%$ for ResNet56 under the strongest IFGSM attack. Furthermore, We provide an intuitive explanation of our defense by analyzing the geometry of the feature space.

Bao Wang, Alex T. Lin, Wei Zhu, Penghang Yin, Andrea L. Bertozzi, Stanley J. Osher• 2018

Related benchmarks

TaskDatasetResultRank
Anti-customizationVGG-Face2 (test)--
16
Image PurificationVGGFace2 EASPL (test)
IMS-0.1
12
Image PurificationVGGFace2 MetaCloak (test)
IMS-0.11
12
Image PurificationVGGFace2 Glaze (test)
IMS-0.11
12
Image PurificationVGGFace2 FSMG (test)
IMS-0.12
12
Image PurificationVGGFace2 ASPL (test)
IMS-0.16
12
Image PurificationVGGFace2 AdvDM (test)
IMS-0.12
12
Image PurificationVGGFace2 PhotoGuard (test)
IMS-0.15
12
Showing 8 of 8 rows

Other info

Follow for update