Efficient Certified Defenses Against Patch Attacks on Image Classifiers

02/08/2021
by   Jan-Hendrik Metzen, et al.
0

Adversarial patches pose a realistic threat model for physical world attacks on autonomous systems via their perception component. Autonomous systems in safety-critical domains such as automated driving should thus contain a fail-safe fallback component that combines certifiable robustness against patches with efficient inference while maintaining high performance on clean inputs. We propose BagCert, a novel combination of model architecture and certification procedure that allows efficient certification. We derive a loss that enables end-to-end optimization of certified robustness against patches of different sizes and locations. On CIFAR10, BagCert certifies 10.000 examples in 43 seconds on a single GPU and obtains 86 against 5x5 patches.

READ FULL TEXT

page 3

page 14

page 15

research
01/05/2022

On the Real-World Adversarial Robustness of Real-Time Semantic Segmentation Models for Autonomous Driving

The existence of real-world adversarial examples (commonly in the form o...
research
03/14/2020

Certified Defenses for Adversarial Patches

Adversarial patch attacks are among one of the most practical threat mod...
research
04/20/2023

Jedi: Entropy-based Localization and Removal of Adversarial Patches

Real-world adversarial physical patches were shown to be successful in c...
research
11/19/2021

Zero-Shot Certified Defense against Adversarial Patches with Vision Transformers

Adversarial patch attack aims to fool a machine learning model by arbitr...
research
03/16/2021

Adversarial YOLO: Defense Human Detection Patch Attacks via Detecting Adversarial Patches

The security of object detection systems has attracted increasing attent...
research
03/03/2023

AdvART: Adversarial Art for Camouflaged Object Detection Attacks

A majority of existing physical attacks in the real world result in cons...
research
03/18/2023

Detection of Uncertainty in Exceedance of Threshold (DUET): An Adversarial Patch Localizer

Development of defenses against physical world attacks such as adversari...

Please sign up or login with your details

Forgot password? Click here to reset