On Reducing Adversarial Vulnerability with Data Dependent Stochastic Resonance

0Citations
Citations of this article
3Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Neural networks are vulnerable to adversarial attacks formed by minuscule perturbations to the original data. These perturbations lead to significant performance degradation. Previous works on defenses against adversarial evasion attacks typically involve pre-processing input data at training or testing time, or modifications to the objective function optimized during the training. In contrast, relatively fewer defense methods focus on modifying the topology and functionality of the underlying defended neural network. Additionally, prior theoretical examinations of the geometry of adversarial examples reveal a challenging and intrinsic trade-off between adversarial and benign accuracy. We introduce a novel modification to a traditional feed-forward convolutional neural network that embeds uncertainty within the network's hidden representations in a learned and data-dependent manner. Our proposed alteration renders the network significantly more resilient than comparably computationally expensive alternatives. Further, the empirical investigation of the proposed defense demonstrates that, unlike prior defense techniques that are comparable to state-of-the-art, the stochastic resonance effect improves adversarial accuracy without significant degradation in benign accuracy.

Cite

CITATION STYLE

APA

Schwartz, D., & Ditzler, G. (2022). On Reducing Adversarial Vulnerability with Data Dependent Stochastic Resonance. In Proceedings of the 2022 IEEE Symposium Series on Computational Intelligence, SSCI 2022 (pp. 1334–1341). Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1109/SSCI51031.2022.10022248

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free