Exploiting Joint Robustness to Adversarial Perturbations

被引:22
作者
Dabouei, Ali [1 ]
Soleymani, Sobhan [1 ]
Taherkhani, Fariborz [1 ]
Dawson, Jeremy [1 ]
Nasrabadi, Nasser M. [1 ]
机构
[1] West Virginia Univ, Morgantown, WV 26506 USA
来源
2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR) | 2020年
关键词
NORM;
D O I
10.1109/CVPR42600.2020.00120
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recently, ensemble models have demonstrated empirical capabilities to alleviate the adversarial vulnerability. In this paper, we exploit first-order interactions within ensembles to formalize a reliable and practical defense. We introduce a scenario of interactions that certifiably improves the robustness according to the size of the ensemble, the diversity of the gradient directions, and the balance of the member's contribution to the robustness. We present a joint gradient phase and magnitude regularization (GPMR) as a vigorous approach to impose the desired scenario of interactions among members of the ensemble. Through extensive experiments, including gradient-based and gradient-free evaluations on several datasets and network architectures, we validate the practical effectiveness of the proposed approach compared to the previous methods. Furthermore, we demonstrate that GPMR is orthogonal to other defense strategies developed for single classifiers and their combination can further improve the robustness of ensembles.
引用
收藏
页码:1119 / 1128
页数:10
相关论文
共 44 条
[1]  
Abbasi Mahdieh, 2017, ARXIV170206856
[2]  
[Anonymous], 2019, ARXIV190108846
[3]  
Athalye A, 2018, PR MACH LEARN RES, V80
[4]  
Athalye A, 2018, PR MACH LEARN RES, V80
[5]  
Bagnall A, 2017, ARXIV PREPRINT ARXIV
[6]  
Brown T.B., 2017, arXiv preprint arXiv:1712.09665.
[7]  
Carlini N., 2017, P AISEC, P3
[8]   Towards Evaluating the Robustness of Neural Networks [J].
Carlini, Nicholas ;
Wagner, David .
2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, :39-57
[9]  
Chellappa R., 2018, ICLR
[10]  
Chen PY, 2018, AAAI CONF ARTIF INTE, P10