2018

Combating Adversarial Attacks Using Sparse Representations

Gopalakrishnan, Soorya, Marzi, Zhinus, Madhow, Upamanyu et al.

Understand

It is by now well-known that small adversarial perturbations can induce classification errors in deep neural networks (DNNs).

  • In this paper, we make the case that sparse representations of the input data are a crucial tool for combating such attacks.
  • For linear classifiers, we show that a sparsifying front end is provably effective against $\ell_{\infty}$-bounded attacks, reducing output distortion due to the attack by a factor of roughly $K / N$ where $N$ is the data dimension and $K$ is the sparsity level.
  • We then extend this concept to DNNs, showing that a "locally linear" model can be used to develop a theoretical foundation for crafting attacks and defenses.

Built on

  • Biorthogonal bases of compactly supported wavelets

    Albert Cohen, Ingrid Daubechies, and J-C Feauveau · 1992

    Earlier work this paper cites.

  • Gradient-based learning applied to document recognition

    Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998

    Earlier work this paper cites.

  • Intriguing properties of neural networks

    Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014

    Earlier work this paper cites.

  • Explaining and harnessing adversarial examples

    Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015

    Earlier work this paper cites.

  • Neural Networks and Deep Learning

    Michael A Nielsen · 2015

    Earlier work this paper cites.

Similar

Then

Beyond the bibliography

alphaXiv searches the wider corpus for related work and actual follow-ups.

Open on alphaXiv

alphaXiv is searching for related work…