2020/05/17 by Mahdieh Abbasi, Abbasi, Mahdieh, Arezoo Rajabi +5
Computer Science · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Cryptography and Security (cs.CR) #Explainable Artificial Intelligence (XAI) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Machine Learning (stat.ML)
paper · pdf · doi:10.48550/arxiv.2005.08321
openalex publication_date 2020/05/17 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
We aim at demonstrating the influence of diversity in the ensemble of CNNs on\nthe detection of black-box adversarial instances and hardening the generation\nof white-box adversarial attacks. To this end, we propose an ensemble of\ndiverse specialized CNNs along with a simple voting mechanism. The diversity in\nthis ensemble creates a gap between the predictive confidences of adversaries\nand those of clean samples, making adversaries detectable. We then analyze how\ndiversity in such an ensemble of specialists may mitigate the risk of the\nblack-box and white-box adversarial examples. Using MNIST and CIFAR-10, we\nempirically verify the ability of our ensemble to detect a large portion of\nwell-known black-box adversarial examples, which leads to a significant\nreduction in the risk rate of adversaries, at the expense of a small increase\nin the risk rate of clean samples. Moreover, we show that the success rate of\ngenerating white-box attacks by our ensemble is remarkably decreased compared\nto a vanilla CNN and an ensemble of vanilla CNNs, highlighting the beneficial\nrole of diversity in the ensemble for developing more robust models.\n