Benchmarking Adversarial Robustness on Image Classification

被引:145
作者
Dong, Yinpeng [1 ]
Fu, Qi-An [1 ]
Yang, Xiao [1 ]
Pang, Tianyu [1 ]
Su, Hang [1 ]
Xiao, Zihao [2 ]
Zhu, Jun [1 ]
机构
[1] Tsinghua Univ, Dept Comp Sci & Tech, BNRist Ctr, Inst AI,THBI Lab, Beijing 100084, Peoples R China
[2] RealAI, London, England
来源
2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR) | 2020年
关键词
D O I
10.1109/CVPR42600.2020.00040
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks are vulnerable to adversarial examples, which becomes one of the most important research problems in the development of deep learning. While a lot of efforts have been made in recent years, it is of great significance to perform correct and complete evaluations of the adversarial attack and defense algorithms. In this paper, we establish a comprehensive, rigorous, and coherent benchmark to evaluate adversarial robustness on image classification tasks. After briefly reviewing plenty of representative attack and defense methods, we perform large-scale experiments with two robustness curves as the fair-minded evaluation criteria to fully understand the performance of these methods. Based on the evaluation results, we draw several important findings that can provide insights for future research, including: 1) The relative robustness between models can change across different attack configurations, thus it is encouraged to adopt the robustness curves to evaluate adversarial robustness; 2) As one of the most effective defense techniques, adversarial training can generalize across different threat models; 3) Randomization-based defenses are more robust to query-based black-box attacks.
引用
收藏
页码:318 / 328
页数:11
相关论文
共 67 条
[51]   The sensitizing effects of NO2 and NO on methane low temperature oxidation in a jet stirred reactor [J].
Song, Y. ;
Marrodan, L. ;
Vin, N. ;
Herbinet, O. ;
Assaf, E. ;
Fittschen, C. ;
Stagni, A. ;
Faravelli, T. ;
Alzueta, M. U. ;
Battin-Leclerc, F. .
PROCEEDINGS OF THE COMBUSTION INSTITUTE, 2019, 37 (01) :667-675
[52]  
Song Yang, 2018, ADV NEURAL INFORM PR
[53]  
Szegedy C., 2014, ICLR, P1
[54]   Rethinking the Inception Architecture for Computer Vision [J].
Szegedy, Christian ;
Vanhoucke, Vincent ;
Ioffe, Sergey ;
Shlens, Jon ;
Wojna, Zbigniew .
2016 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2016, :2818-2826
[55]   Caregiver burden and family functioning in different neurological diseases [J].
Tramonti, Francesco ;
Bonfiglio, Luca ;
Bongioanni, Paolo ;
Belviso, Cristina ;
Fanciullacci, Chiara ;
Rossi, Bruno ;
Chisari, Carmelo ;
Carboncini, Maria Chiara .
PSYCHOLOGY HEALTH & MEDICINE, 2019, 24 (01) :27-34
[56]  
Uesato J, 2018, PR MACH LEARN RES, V80
[57]  
Wong E, 2018, PR MACH LEARN RES, V80
[58]  
Xiao Kai Y, 2019, ICLR
[59]   The LED-ID Detection and Recognition Method Based on Visible Light Positioning Using Proximity Method [J].
Xie, Canyu ;
Guan, Weipeng ;
Wu, Yuxiang ;
Fang, Liangtao ;
Cai, Ye .
IEEE PHOTONICS JOURNAL, 2018, 10 (02)
[60]   Improving Transferability of Adversarial Examples with Input Diversity [J].
Xie, Cihang ;
Zhang, Zhishuai ;
Zhou, Yuyin ;
Bai, Song ;
Wang, Jianyu ;
Ren, Zhou ;
Yuille, Alan .
2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, :2725-2734