Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search Abhimanyu Dubey, Laurens van der Maaten, I. Zeki Yalniz, Yixuan Li and Dhruv Mahajan
Adversarial Images adversarial “swan” “pelican” perturbation
Nearest—Neighbors Defense • Adversarial perturbations move the input away from the image “manifold”. • KNN Defense : Project the image back on to the manifold. adversarial image clean image nearest neighbors Approximation of manifold by tens of billions of images
Nearest—Neighbors Defense adversarial input “swan” “pelican” KNN web-scale database
Effect of Scale PGD Attack Log-linear relationship.
Comparison with other defenses Attack Type: PGD Model: ResNet-50
KNN Based Attack Separate database available to attacker. Overlap : %-age of images shared between attacker’s and defense database Data obfuscation is a viable defense strategy.
Thank You! Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search Arxiv: https://arxiv.org/pdf/1903.01612.pdf Poster Session 3.1, Poster #87, 10:00 AM Thursday.
Recommend
More recommend