Defending Against Multiple and Unforeseen Adversarial Videos

09/11/2020
by   Shao-Yuan Lo, et al.
1

Adversarial examples of deep neural networks have been actively investigated on image-based classification, segmentation and detection tasks. However, adversarial robustness of video models still lacks exploration. While several studies have proposed how to generate adversarial videos, only a handful of approaches pertaining to the defense strategies have been published in the literature. Furthermore, these defense methods are limited to a single perturbation type and often fail to provide robustness to Lp-bounded attacks and physically realizable attacks simultaneously. In this paper, we propose one of the first defense solutions against multiple adversarial video types for video classification. The proposed approach performs adversarial training with multiple types of video adversaries using independent batch normalizations (BNs), and recognizes different adversaries by an adversarial video detector. During inference, a switch module sends an input to a proper batch normalization branch according to the detected attack type. Compared to conventional adversarial training, our method exhibits stronger robustness to multiple and even unforeseen adversarial videos and provides higher classification accuracy.

READ FULL TEXT

page 1

page 2

page 5

page 7

research
04/30/2019

Adversarial Training and Robustness for Multiple Perturbations

Defenses against adversarial examples, such as adversarial training, are...
research
08/21/2019

Testing Robustness Against Unforeseen Adversaries

Considerable work on adversarial defense has studied robustness to a fix...
research
09/17/2020

MultAV: Multiplicative Adversarial Videos

The majority of adversarial machine learning research focuses on additiv...
research
12/08/2020

Overcomplete Representations Against Adversarial Videos

Adversarial robustness of deep neural networks is an extensively studied...
research
09/20/2019

Defending Against Physically Realizable Attacks on Image Classification

We study the problem of defending deep neural network approaches for ima...
research
09/11/2019

Identifying and Resisting Adversarial Videos Using Temporal Consistency

Video classification is a challenging task in computer vision. Although ...
research
05/18/2023

Adversarial Amendment is the Only Force Capable of Transforming an Enemy into a Friend

Adversarial attack is commonly regarded as a huge threat to neural netwo...

Please sign up or login with your details

Forgot password? Click here to reset