Smoothed Inference for Adversarially-Trained Models
Explore this paper's citation graph
Summary
This work examines the application of randomized smoothing as a way to improve performance on unperturbed data as well as to increase robustness to adversarial attacks, and finds it lends itself well for trading-off between the model inference complexity and its performance.
- Type
- preprint
- Published
- 2019-11-17
- Cited by
- 2
- References
- 57
- Access
- Open access
- OpenAlex
- https://openalex.org/W2988677439
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:208138377
Keywords
Computer science, Smoothing, Adversarial system, Inference, Classifier (UML)
References
- Intriguing properties of neural networks
- Natural Evolution Strategies
- Improving the Robustness of Deep Neural Networks via Stability Training
- Towards Evaluating the Robustness of Neural Networks
- Practical Black-Box Attacks against Machine Learning
- Towards Deep Learning Models Resistant to Adversarial Attacks
- ZOO: Zeroth Order Optimization Based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Provable defenses against adversarial examples via the convex outer adversarial polytope
- Towards Robust Neural Networks via Random Self-ensemble
- Audio Adversarial Examples: Targeted Attacks on Speech-to-Text
- Adversarial Spheres
- Adversarial Patch
- Generating 3D Adversarial Point Clouds
- Parametric Noise Injection: Trainable Randomness to Improve Deep Neural Network Robustness Against Adversarial Attack
- Decoupling Direction and Norm for Efficient Gradient-Based L2 Adversarial Attacks and Defenses
- Certified Adversarial Robustness via Randomized Smoothing
- Theoretically Principled Trade-off between Robustness and Accuracy
- Daedalus: Breaking Non-Maximum Suppression in Object Detection via Adversarial Examples
- Defending against Whitebox Adversarial Attacks via Randomized Discretization
- Adversarial Training with Voronoi Constraints
Cited by
Related papers
- Densely Connected Networks with Smoothed Labels Regularization for Tea Diseases Detections
- Global Adversarial Attacks for Assessing Deep Learning Robustness
- Developing and Defeating Adversarial Examples
- A smoothing and regularization predictor-corrector method for nonlinear inequalities
- Generating adversarial examples for DNN using pooling layers
- Adversarial Perturbation Defense on Deep Neural Networks
- A Brief Comparison Between White Box, Targeted Adversarial Attacks in Deep Neural Networks
- Efficient Defenses Against Adversarial Attacks