conference-paper
Ensemble of Key-Based Models: Defense Against Black-Box Adversarial Attacks
Research footprint
At a glance
- Citations
- 12
- References
- 62
- Comments
- 0
Paper overview
Abstract
We propose a voting ensemble of models trained by using block-wise transformed images with secret keys against black-box attacks. Although key-based adversarial defenses were effective against gradient-based (white-box) attacks, they cannot defend against gradient-free (black-box) attacks without requiring any secret keys. In the proposed ensemble, a number of models are trained by using images transformed with different keys and block sizes, and then a voting ensemble is applied to the models. Experimental results show that the proposed defense achieves a clean accuracy of 95.56 % and an attack success rate of less than 9 % under attacks with a noise distance of 8/255 on the CIFAR-10 dataset.
Record transparency
Publication details
- DOI
- 10.1109/gcce53005.2021.9621775
- OpenAlex
- W4200625937
- Document type
- conference-paper
- Language
- EN
- Source
- 2021 IEEE 10th Global Conference on Consumer Electronics (GCCE)
- Last metadata update
Comments
Log in to join the discussion.