defense against adversarial images using web scale
play

Defense Against Adversarial Images using Web-Scale Nearest-Neighbor - PowerPoint PPT Presentation

Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search Abhimanyu Dubey, Laurens van der Maaten, I. Zeki Yalniz, Yixuan Li and Dhruv Mahajan Adversarial Images adversarial swan pelican perturbation


  1. Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search Abhimanyu Dubey, Laurens van der Maaten, I. Zeki Yalniz, Yixuan Li and Dhruv Mahajan

  2. Adversarial Images adversarial “swan” “pelican” perturbation

  3. Nearest—Neighbors Defense • Adversarial perturbations move the input away from the image “manifold”. • KNN Defense : Project the image back on to the manifold. adversarial image clean image nearest neighbors Approximation of manifold by tens of billions of images

  4. Nearest—Neighbors Defense adversarial input “swan” “pelican” KNN web-scale database

  5. Effect of Scale PGD Attack Log-linear relationship.

  6. Comparison with other defenses Attack Type: PGD Model: ResNet-50

  7. KNN Based Attack Separate database available to attacker. Overlap : %-age of images shared between attacker’s and defense database Data obfuscation is a viable defense strategy.

  8. Thank You! Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search Arxiv: https://arxiv.org/pdf/1903.01612.pdf Poster Session 3.1, Poster #87, 10:00 AM Thursday.

Recommend


More recommend