conference-paper

Ensemble of Key-Based Models: Defense Against Black-Box Adversarial Attacks

  • 2021 IEEE 10th Global Conference on Consumer Electronics (GCCE)
Research footprint

At a glance

Citations
12
References
62
Comments
0
Paper overview

Abstract

We propose a voting ensemble of models trained by using block-wise transformed images with secret keys against black-box attacks. Although key-based adversarial defenses were effective against gradient-based (white-box) attacks, they cannot defend against gradient-free (black-box) attacks without requiring any secret keys. In the proposed ensemble, a number of models are trained by using images transformed with different keys and block sizes, and then a voting ensemble is applied to the models. Experimental results show that the proposed defense achieves a clean accuracy of 95.56 % and an attack success rate of less than 9 % under attacks with a noise distance of 8/255 on the CIFAR-10 dataset.

Record transparency

Publication details

DOI
10.1109/gcce53005.2021.9621775
OpenAlex
W4200625937
Document type
conference-paper
Language
EN
Source
2021 IEEE 10th Global Conference on Consumer Electronics (GCCE)
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.