Where Does the Robustness Come from?: A Study of the Transformation-based Ensemble Defence

1Citations
Citations of this article
11Readers
Mendeley users who have this article in their library.
Get full text

Abstract

This paper aims to provide a thorough study on the effectiveness of the transformation-based ensemble defence for image classification and its reasons. It has been empirically shown that they can enhance the robustness against evasion attacks, while there is little analysis on the reasons. In particular, it is not clear whether the robustness improvement is a result of transformation or ensemble. In this paper, we design two adaptive attacks to better evaluate the transformation-based ensemble defence. We conduct experiments to show that 1) the transferability of adversarial examples exists among the models trained on data records after different reversible transformations; 2) the robustness gained through transformation-based ensemble is limited; 3) this limited robustness is mainly from the irreversible transformations rather than the ensemble of a number of models; and 4) blindly increasing the number of sub-models in a transformation-based ensemble does not bring extra robustness gain.

Cite

CITATION STYLE

APA

Liao, C., Cheng, Y., Fang, C., & Shi, J. (2020). Where Does the Robustness Come from?: A Study of the Transformation-based Ensemble Defence. In AISec 2020 - Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security (pp. 1–12). Association for Computing Machinery, Inc. https://doi.org/10.1145/3411508.3421380

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free