REVIEW 2 cited by
HyperNetworks with statistical filtering for defending adversarial examples
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Deep learning algorithms have been known to be vulnerable to adversarial perturbations in various tasks such as image classification. This problem was addressed by employing several defense methods for detection and rejection of particular types of attacks. However, training and manipulating networks according to particular defense schemes increases computational complexity of the learning algorithms. In this work, we propose a simple yet effective method to improve robustness of convolutional neural networks (CNNs) to adversarial attacks by using data dependent adaptive convolution kernels. To this end, we propose a new type of HyperNetwork in order to employ statistical properties of input data and features for computation of statistical adaptive maps. Then, we filter convolution weights of CNNs with the learned statistical maps to compute dynamic kernels. Thereby, weights and kernels are collectively optimized for learning of image classification models robust to adversarial attacks without employment of additional target detection and rejection algorithms. We empirically demonstrate that the proposed method enables CNNs to spontaneously defend against different types of attacks, e.g. attacks generated by Gaussian noise, fast gradient sign methods (Goodfellow et al., 2014) and a black-box attack(Narodytska & Kasiviswanathan, 2016).
Forward citations
Cited by 2 Pith papers
-
NeuMoSync: End-to-End Neuromodulatory Control for Plasticity and Adaptability in Continual Learning
A global neuromodulatory controller with per-neuron weight, activation, and offset modulation preserves plasticity and improves forward and backward adaptation in continual learning.
-
Amortized In-Context Bayesian Posterior Estimation
A benchmark of in-context Bayesian posterior estimators shows the reverse-KL objective with transformers and normalizing flows outperforms forward-KL neural posterior estimation on predictive and out-of-distribution tasks.
Discussion (0). Continue with ORCID to comment.