Header menu link for other important links
X
BatchOut: Batch-level feature augmentation to improve robustness to adversarial examples
A. Subramanya, , R.V. Babu
Published in Association for Computing Machinery
2018
Abstract
Machine Learning models are known to be susceptible to small but structured changes to their inputs that can result in wrong inferences. It has been shown that such samples, called adversarial samples, can be created rather easily for standard neural network architectures. These adversarial samples pose a serious threat for deploying state-of-the-art deep neural network models in the real world. We propose a feature augmentation technique called BatchOut to learn robust models towards such examples. The proposed approach is a generic feature augmentation technique that is not specific to any adversary and handles multiple attacks. We evaluate our algorithm on benchmark datasets and architectures to show that models trained using our method are less susceptible to adversaries created using multiple methods. © 2018 ACM.
About the journal
JournalACM International Conference Proceeding Series
PublisherAssociation for Computing Machinery