While deep neural networks have been achieving state-of-the-art performance\nacross a wide variety of applications, their vulnerability to adversarial\nattacks limits their widespread deployment for safety-critical applications.\nAlongside other adversarial defense approaches being investigated, there has\nbeen a very recent interest in improving adversarial robustness in deep neural\nnetworks through the introduction of perturbations during the training process.\nHowever, such methods leverage fixed, pre-defined perturbations and require\nsignificant hyper-parameter tuning that makes them very difficult to leverage\nin a general fashion. In this study, we introduce Learn2Perturb, an end-to-end\nfeature perturbation learning approach for improving the adversarial robustness\nof deep neural networks. More specifically, we introduce novel\nperturbation-injection modules that are incorporated at each layer to perturb\nthe feature space and increase uncertainty in the network. This feature\nperturbation is performed at both the training and the inference stages.\nFurthermore, inspired by the Expectation-Maximization, an alternating\nback-propagation training algorithm is introduced to train the network and\nnoise parameters consecutively. Experimental results on CIFAR-10 and CIFAR-100\ndatasets show that the proposed Learn2Perturb method can result in deep neural\nnetworks which are $4-7\\%$ more robust on $l_{\\infty}$ FGSM and PDG adversarial\nattacks and significantly outperforms the state-of-the-art against $l_2$ $C\\&W$\nattack and a wide range of well-known black-box attacks.\n
Paper
References (100)
Scroll for more · 38 remaining