Adversarial Robustness: Softmax versus Openmax

08/05/2017
by   Andras Rozsa, et al.
0

Deep neural networks (DNNs) provide state-of-the-art results on various tasks and are widely used in real world applications. However, it was discovered that machine learning models, including the best performing DNNs, suffer from a fundamental problem: they can unexpectedly and confidently misclassify examples formed by slightly perturbing otherwise correctly recognized inputs. Various approaches have been developed for efficiently generating these so-called adversarial examples, but those mostly rely on ascending the gradient of loss. In this paper, we introduce the novel logits optimized targeting system (LOTS) to directly manipulate deep features captured at the penultimate layer. Using LOTS, we analyze and compare the adversarial robustness of DNNs using the traditional Softmax layer with Openmax, which was designed to provide open set recognition by defining classes derived from deep representations, and is claimed to be more robust to adversarial perturbations. We demonstrate that Openmax provides less vulnerable systems than Softmax to traditional attacks, however, we show that it can be equally susceptible to more sophisticated adversarial generation techniques that directly work on deep representations.

READ FULL TEXT

page 6

page 7

page 8

research
11/18/2016

LOTS about Attacking Deep Features

Deep neural networks provide state-of-the-art performance on various tas...
research
11/21/2021

Efficient Softmax Approximation for Deep Neural Networks with Attention Mechanism

There has been a rapid advance of custom hardware (HW) for accelerating ...
research
01/04/2018

Facial Attributes: Accuracy and Adversarial Robustness

Facial attributes, emerging soft biometrics, must be automatically and r...
research
11/01/2018

Improving Adversarial Robustness by Encouraging Discriminative Features

Deep neural networks (DNNs) have achieved state-of-the-art results in va...
research
05/27/2019

Radial Prediction Layer

For a broad variety of critical applications, it is essential to know ho...
research
03/23/2022

Enhancing Classifier Conservativeness and Robustness by Polynomiality

We illustrate the detrimental effect, such as overconfident decisions, t...
research
04/17/2020

One-vs-Rest Network-based Deep Probability Model for Open Set Recognition

Unknown examples that are unseen during training often appear in real-wo...

Please sign up or login with your details

Forgot password? Click here to reset