AID-Purifier: A Light Auxiliary Network for Boosting Adversarial Defense

07/14/2021
by   Duhun Hwang, et al.
0

We propose an AID-purifier that can boost the robustness of adversarially-trained networks by purifying their inputs. AID-purifier is an auxiliary network that works as an add-on to an already trained main classifier. To keep it computationally light, it is trained as a discriminator with a binary cross-entropy loss. To obtain additionally useful information from the adversarial examples, the architecture design is closely related to information maximization principles where two layers of the main classification network are piped to the auxiliary network. To assist the iterative optimization procedure of purification, the auxiliary network is trained with AVmixup. AID-purifier can be used together with other purifiers such as PixelDefend for an extra enhancement. The overall results indicate that the best performing adversarially-trained networks can be enhanced by the best performing purification networks, where AID-purifier is a competitive candidate that is light and robust.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/17/2019

HAD-GAN: A Human-perception Auxiliary Defense GAN model to Defend Adversarial Examples

Adversarial examples reveal the vulnerability and unexplained nature of ...
research
01/04/2017

SalGAN: Visual Saliency Prediction with Generative Adversarial Networks

We introduce SalGAN, a deep convolutional neural network for visual sali...
research
10/30/2018

Improved Network Robustness with Adversary Critic

Ideally, what confuses neural network should be confusing to humans. How...
research
11/08/2020

Image Clustering using an Augmented Generative Adversarial Network and Information Maximization

Image clustering has recently attracted significant attention due to the...
research
06/21/2018

Gradient Adversarial Training of Neural Networks

We propose gradient adversarial training, an auxiliary deep learning fra...
research
06/12/2021

Adversarial Robustness via Fisher-Rao Regularization

Adversarial robustness has become a topic of growing interest in machine...
research
10/02/2020

Maximal benefits and possible detrimental effects of binary decision aids

Binary decision aids, such as alerts, are a simple and widely used form ...

Please sign up or login with your details

Forgot password? Click here to reset