2018

Defense Against Adversarial Attacks with Saak Transform

Song, Sibo, Chen, Yueru, Cheung, Ngai-Man et al.

Understand

Deep neural networks (DNNs) are known to be vulnerable to adversarial perturbations, which imposes a serious threat to DNN-based decision systems.

  • In this paper, we propose to apply the lossy Saak transform to adversarially perturbed images as a preprocessing tool to defend against adversarial attacks.
  • Saak transform is a recently-proposed state-of-the-art for computing the spatial-spectral representations of input images.
  • Empirically, we observe that outputs of the Saak transform are very discriminative in differentiating adversarial examples from clean ones.

Reading the bibliography…