← all papers · overview

Democratic Training Against Universal Adversarial Perturbations

Abstract

Despite their advances and success, real-world deep neural networks are known to be vulnerable to adversarial attacks. Universal adversarial perturbation, an input-agnostic attack, poses a serious threat for them to be deployed in security-sensitive systems. In this case, a single universal adversarial perturbation deceives the model on a range of clean inputs without requiring input-specific optimization, which makes it particularly threatening. In this work, we observe that universal adversarial perturbations usually lead to abnormal entropy spectrum in hidden layers, which suggests that the prediction is dominated by a small number of ``feature'' in such cases (rather than democratically by many features). Inspired by this, we propose an efficient yet effective defense method for mitigating UAPs called *Democratic Training* by performing entropy-based model enhancement to suppress the effect of the universal adversarial perturbations in a given model. *Democratic Training* is evalua

Related papers

Ranked by semantic similarity — how closely each paper's abstract matches this one (100% = near-identical topic).