Vax-a-Net: Training-time Defence Against Adversarial Patch Attacks

09/17/2020
by   T. Gittings, et al.
9

We present Vax-a-Net; a technique for immunizing convolutional neural networks (CNNs) against adversarial patch attacks (APAs). APAs insert visually overt, local regions (patches) into an image to induce misclassification. We introduce a conditional Generative Adversarial Network (GAN) architecture that simultaneously learns to synthesise patches for use in APAs, whilst exploiting those attacks to adapt a pre-trained target CNN to reduce its susceptibility to them. This approach enables resilience against APAs to be conferred to pre-trained models, which would be impractical with conventional adversarial training due to the slow convergence of APA methods. We demonstrate transferability of this protection to defend against existing APAs, and show its efficacy across several contemporary CNN architectures.

READ FULL TEXT

page 2

page 5

page 6

page 11

research
04/20/2023

Jedi: Entropy-based Localization and Removal of Adversarial Patches

Real-world adversarial physical patches were shown to be successful in c...
research
07/15/2022

Feasibility of Inconspicuous GAN-generated Adversarial Patches against Object Detection

Standard approaches for adversarial patch generation lead to noisy consp...
research
01/26/2021

The Effect of Class Definitions on the Transferability of Adversarial Attacks Against Forensic CNNs

In recent years, convolutional neural networks (CNNs) have been widely u...
research
02/17/2022

Developing Imperceptible Adversarial Patches to Camouflage Military Assets From Computer Vision Enabled Technologies

Convolutional neural networks (CNNs) have demonstrated rapid progress an...
research
11/18/2020

Adversarial Profiles: Detecting Out-Distribution Adversarial Samples in Pre-trained CNNs

Despite high accuracy of Convolutional Neural Networks (CNNs), they are ...
research
06/28/2023

Boosting Adversarial Transferability with Learnable Patch-wise Masks

Adversarial examples have raised widespread attention in security-critic...
research
09/14/2017

The Conditional Analogy GAN: Swapping Fashion Articles on People Images

We present a novel method to solve image analogy problems : it allows to...

Please sign up or login with your details

Forgot password? Click here to reset