preprint Open access

Constant Random Perturbations Provide Adversarial Robustness with Minimal Effect on Accuracy

  • arXiv (Cornell University)
  • Cornell University
Research footprint

At a glance

Citations
0
References
23
Comments
0
Paper overview

Öz

This paper proposes an attack-independent (non-adversarial training) technique for improving adversarial robustness of neural network models, with minimal loss of standard accuracy. We suggest creating a neighborhood around each training example, such that the label is kept constant for all inputs within that neighborhood. Unlike previous work that follows a similar principle, we apply this idea by extending the training set with multiple perturbations for each training example, drawn from within the neighborhood. These perturbations are model independent, and remain constant throughout the entire training process. We analyzed our method empirically on MNIST, SVHN, and CIFAR-10, under different attacks and conditions. Results suggest that the proposed approach improves standard accuracy over other defenses while having increased robustness compared to vanilla adversarial training.

Record transparency

Publication details

DOI
10.48550/arxiv.2103.08265
OpenAlex
W3136095779
Document type
preprint
Language
EN
Source
arXiv (Cornell University)
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.