Minimax Defense against Gradient-based Adversarial Attacks

02/04/2020
by   Blerta Lindqvist, et al.
0

State-of-the-art adversarial attacks are aimed at neural network classifiers. By default, neural networks use gradient descent to minimize their loss function. The gradient of a classifier's loss function is used by gradient-based adversarial attacks to generate adversarially perturbed images. We pose the question whether another type of optimization could give neural network classifiers an edge. Here, we introduce a novel approach that uses minimax optimization to foil gradient-based adversarial attacks. Our minimax classifier is the discriminator of a generative adversarial network (GAN) that plays a minimax game with the GAN generator. In addition, our GAN generator projects all points onto a manifold that is different from the original manifold since the original manifold might be the cause of adversarial attacks. To measure the performance of our minimax defense, we use adversarial attacks - Carlini Wagner (CW), DeepFool, Fast Gradient Sign Method (FGSM) - on three datasets: MNIST, CIFAR-10 and German Traffic Sign (TRAFFIC). Against CW attacks, our minimax defense achieves 98.07 (CIFAR-10-default 83.14 attacks, our minimax defense achieves 98.87 94.57 (CIFAR-10) and 81.41 significant shift in defense strategy for neural network classifiers.

READ FULL TEXT

page 2

page 5

research
12/08/2018

AutoGAN: Robust Classifier Against Adversarial Attacks

Classifiers fail to classify correctly input images that have been purpo...
research
09/04/2023

Toward Defensive Letter Design

A major approach for defending against adversarial attacks aims at contr...
research
06/08/2020

Tricking Adversarial Attacks To Fail

Recent adversarial defense approaches have failed. Untargeted gradient-b...
research
05/27/2018

Defending Against Adversarial Attacks by Leveraging an Entire GAN

Recent work has shown that state-of-the-art models are highly vulnerable...
research
07/21/2019

Improving Neural Network Classifier using Gradient-based Floating Centroid Method

Floating centroid method (FCM) offers an efficient way to solve a fixed-...
research
11/12/2021

Adversarially Robust Learning for Security-Constrained Optimal Power Flow

In recent years, the ML community has seen surges of interest in both ad...
research
05/29/2022

Mixture GAN For Modulation Classification Resiliency Against Adversarial Attacks

Automatic modulation classification (AMC) using the Deep Neural Network ...

Please sign up or login with your details

Forgot password? Click here to reset