conference-paper

SymDNN: Simple & Effective Adversarial Robustness for Embedded Systems

  • 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW)
Research footprint

At a glance

الاستشهادات
3
المراجع
100
Comments
0
Paper overview

Abstract

We propose SymDNN, a Deep Neural Network (DNN) inference scheme, to segment an input image into small patches, replace those patches with representative symbols, and use the reconstructed image for CNN inference. This approach of deconstruction of images, and the reconstruction from cluster centroids trained on clean images, enhances robustness against adversarial attacks. The input transform used in SymDNN is learned from very large datasets, making it difficult to approximate for adaptive adversarial attacks. For example, SymDNN achieves 23% and 42% robust accuracy at L∞attack strengths of 8/255 and 4/255 respectively, against BPDA under a complete white box setting, where most input processing based defenses break completely. SymDNN is not a future-proof adversarial defense that can defend any attack, but it is one of the few readily usable defenses in resource-limited embedded systems that defends against a wide range of attacks. Our code is available at: https://github.com/swadeykgp/SymDNN.

Record transparency

Publication details

DOI
10.1109/cvprw56347.2022.00404
OpenAlex
W4292828971
Document type
conference-paper
Language
EN
Source
2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW)
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.