2019/05/13 by Mayank Singh, Abhishek Sinha, Singh, Mayank +9 · 5 citations
Computer Science · #Advanced Neural Network Applications #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Computer Vision and Pattern Recognition (cs.CV) #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Machine Learning (stat.ML)
paper · pdf · doi:10.48550/arxiv.1905.05186
openalex publication_date 2019/05/13 · openalex created_date 2022/07/29 · openalex updated_date 2026/07/28
Neural networks are vulnerable to adversarial attacks -- small visually\nimperceptible crafted noise which when added to the input drastically changes\nthe output. The most effective method of defending against these adversarial\nattacks is to use the methodology of adversarial training. We analyze the\nadversarially trained robust models to study their vulnerability against\nadversarial attacks at the level of the latent layers. Our analysis reveals\nthat contrary to the input layer which is robust to adversarial attack, the\nlatent layer of these robust models are highly susceptible to adversarial\nperturbations of small magnitude. Leveraging this information, we introduce a\nnew technique Latent Adversarial Training (LAT) which comprises of fine-tuning\nthe adversarially trained models to ensure the robustness at the feature\nlayers. We also propose Latent Attack (LA), a novel algorithm for construction\nof adversarial examples. LAT results in minor improvement in test accuracy and\nleads to a state-of-the-art adversarial accuracy against the universal\nfirst-order adversarial PGD attack which is shown for the MNIST, CIFAR-10,\nCIFAR-100 datasets.\n