Pith. sign in

REVIEW 1 cited by

Resisting Adversarial Attacks in Deep Neural Networks using Diverse Decision Boundaries

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2208.08697 v1 pith:Y4756V4Z submitted 2022-08-18 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords adversarialattacksdeepdiverseensemble-basedmodelbeenboundaries
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The security of deep learning (DL) systems is an extremely important field of study as they are being deployed in several applications due to their ever-improving performance to solve challenging tasks. Despite overwhelming promises, the deep learning systems are vulnerable to crafted adversarial examples, which may be imperceptible to the human eye, but can lead the model to misclassify. Protections against adversarial perturbations on ensemble-based techniques have either been shown to be vulnerable to stronger adversaries or shown to lack an end-to-end evaluation. In this paper, we attempt to develop a new ensemble-based solution that constructs defender models with diverse decision boundaries with respect to the original model. The ensemble of classifiers constructed by (1) transformation of the input by a method called Split-and-Shuffle, and (2) restricting the significant features by a method called Contrast-Significant-Features are shown to result in diverse gradients with respect to adversarial attacks, which reduces the chance of transferring adversarial examples from the original to the defender model targeting the same class. We present extensive experimentations using standard image classification datasets, namely MNIST, CIFAR-10 and CIFAR-100 against state-of-the-art adversarial attacks to demonstrate the robustness of the proposed ensemble-based defense. We also evaluate the robustness in the presence of a stronger adversary targeting all the models within the ensemble simultaneously. Results for the overall false positives and false negatives have been furnished to estimate the overall performance of the proposed methodology.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Optimizing Robustness and Accuracy in Mixture of Experts: A Dual-Model Approach

    cs.LG 2025-02 conditional novelty 6.0 of 10

    A targeted KL penalty on the second-ranked expert plus a jointly trained dual-model blend improves adversarial robustness of mixture-of-experts classifiers with little clean-accuracy loss.

Pith tools