Javascript must be enabled to continue!
Multi-SAP Adversarial Defense for Deep Neural Networks
View through CrossRef
Deep learning models have gained immense popularity for machine learning tasks such as image classification and natural language processing due to their high expressibility. However, they are vulnerable to adversarial samples - perturbed samples that are imperceptible to a human, but can cause the deep learning model to give incorrect predictions with a high confidence. This limitation has been a major deterrent in the deployment of deep learning algorithms in production, specifically in security critical systems. In this project, we followed a game theoretic approach to implement a novel defense strategy, that combines multiple Stochastic Activation Pruning with adversarial training. Our defense accuracy outperforms that of PGD adversarial training, which is known to be the one of the best defenses against several L∞ attacks, by about 6-7%. We are hopeful that our defense strategy can withstand strong attacks leading to more robust deep neural network models.Deep learning models have gained immense popularity for machine learning tasks such as image classification and natural language processing due to their high expressibility. However, they are vulnerable to adversarial samples - perturbed samples that are imperceptible to a human, but can cause the deep learning model to give incorrect predictions with a high confidence. This limitation has been a major deterrent in the deployment of deep learning algorithms in production, specifically in security critical systems. In this project, we followed a game theoretic approach to implement a novel defense strategy, that combines multiple Stochastic Activation Pruning with adversarial training. Our defense accuracy outperforms that of PGD adversarial training, which is known to be the one of the best defenses against several L∞ attacks, by about 6-7%. We are hopeful that our defense strategy can withstand strong attacks leading to more robust deep neural network models.
Society of Visual Informatics
Title: Multi-SAP Adversarial Defense for Deep Neural Networks
Description:
Deep learning models have gained immense popularity for machine learning tasks such as image classification and natural language processing due to their high expressibility.
However, they are vulnerable to adversarial samples - perturbed samples that are imperceptible to a human, but can cause the deep learning model to give incorrect predictions with a high confidence.
This limitation has been a major deterrent in the deployment of deep learning algorithms in production, specifically in security critical systems.
In this project, we followed a game theoretic approach to implement a novel defense strategy, that combines multiple Stochastic Activation Pruning with adversarial training.
Our defense accuracy outperforms that of PGD adversarial training, which is known to be the one of the best defenses against several L∞ attacks, by about 6-7%.
We are hopeful that our defense strategy can withstand strong attacks leading to more robust deep neural network models.
Deep learning models have gained immense popularity for machine learning tasks such as image classification and natural language processing due to their high expressibility.
However, they are vulnerable to adversarial samples - perturbed samples that are imperceptible to a human, but can cause the deep learning model to give incorrect predictions with a high confidence.
This limitation has been a major deterrent in the deployment of deep learning algorithms in production, specifically in security critical systems.
In this project, we followed a game theoretic approach to implement a novel defense strategy, that combines multiple Stochastic Activation Pruning with adversarial training.
Our defense accuracy outperforms that of PGD adversarial training, which is known to be the one of the best defenses against several L∞ attacks, by about 6-7%.
We are hopeful that our defense strategy can withstand strong attacks leading to more robust deep neural network models.
Related Results
NEURAL NETWORKS AND DEEP LEARNING: THEORITICAL INSIGHTS AND FRAMEWORKS
NEURAL NETWORKS AND DEEP LEARNING: THEORITICAL INSIGHTS AND FRAMEWORKS
“NEURAL NETWORKS AND DEEP LEARNING: THEORITICAL INSIGHTS AND FRAMEWORKS” is a comprehensive guide that dives deep into the world of neural networks and their applications in modern...
Achieving digital transformation in public sector organizations: The impact and solutions of SAP implementations
Achieving digital transformation in public sector organizations: The impact and solutions of SAP implementations
Digital transformation in public sector organizations has become a pivotal driver for improving service delivery, operational efficiency, and transparency. SAP implementations offe...
Optimization of Solvent Aided Process
Optimization of Solvent Aided Process
Abstract
The Solvent Aided Process (SAP), described previously by the authors, is an improvement to SAGD that promises to enhance the economics of bitumen/heavy o...
Value of the A2DS2 Score Combined with the Neutrophil-to-lymphocyte Ratio in Predicting Acute Ischemic Stroke-associated Pneumonia
Value of the A2DS2 Score Combined with the Neutrophil-to-lymphocyte Ratio in Predicting Acute Ischemic Stroke-associated Pneumonia
Objective:
We aimed to explore the risk factors for acute ischemic stroke-associated pneumonia (SAP) and evaluate the predictive value of the Age, Atrial fibrillation, Dy...
ProDef-MDS: A Proactive Defense Mechanism Protecting Malware Detection Systems from Adversarial Attacks
ProDef-MDS: A Proactive Defense Mechanism Protecting Malware Detection Systems from Adversarial Attacks
Malware threatens cybersecurity by enabling data theft, unauthorized access, and extortion. Traditional malware detection systems (MDS) struggle with the increasing volume and comp...
Sapsucker Wells as a Keystone Nutritional Resource: Evaluating Methods for Detection of Secondary Sap Consumers
Sapsucker Wells as a Keystone Nutritional Resource: Evaluating Methods for Detection of Secondary Sap Consumers
ABSTRACT
North American sapsuckers are considered double keystone species because they (1) excavate nest cavities that are used by other bird...
An enhanced ensemble defense framework for boosting adversarial robustness of intrusion detection systems
An enhanced ensemble defense framework for boosting adversarial robustness of intrusion detection systems
Abstract
Machine learning (ML) and deep neural networks (DNN) have emerged as powerful tools for enhancing intrusion detection systems (IDS) in cybersecurity. However, re...
Robustness and Security in Deep Learning: Adversarial Attacks and Countermeasures
Robustness and Security in Deep Learning: Adversarial Attacks and Countermeasures
Deep learning models have demonstrated remarkable performance across various domains, yet their susceptibility to adversarial attacks remains a significant concern. In this study, ...

