0% Complete
Home
/
13th International Conference on Computer and Knowledge Engineering
A large input-space-margin approach for adversarial training
Authors :
Reihaneh Nikouei
1
Mohammad Taheri
2
1- Department of Computer Science and Engineering, Shiraz University, Shiraz, Iran.
2- Department of Computer Science and Engineering, Shiraz University, Shiraz, Iran.
Keywords :
Adversarial attack،Large margin،Input space،Defense method
Abstract :
It is shown that machine learning models are vulnerable to adversarial attacks. Therefore, different defense methods such as adversarial training have been proposed to improve models’ robustness against these attacks. Some recent approaches proposed to structurally improve the robustness of the models. For example, large margin methods try to increase a margin, empty of instances, along decision boundaries that structurally increase necessary change to modify a training instance to an adversarial one. However, nonlinear large-margin models, maximize the margin in a high dimensional space although adversarial examples are generated with a little change in the original space. In this paper, a novel mixed approach is proposed, called LIM (Large Input Margin) to improve the robustness of the model by minimizing both structural and empirical risks. Specifically, both training and adversarial example generation are done based on a loss function to maximize the margin in the original feature space even in a non-linear model. The proposed method is evaluated with FGSM and PGD attacks on MNIST and CIFAR10 datasets. The experimental results show that LIM method outperforms the state-of-the-art defense methods significantly and improves adversarial robustness against FGSM and PGD attacks on both datasets.
Papers List
List of archived papers
An Automated Visual Defect Segmentation for Flat Steel Surface Using Deep Neural Networks
Dorna Nourbakhsh Sabet - Mohammad Reza Zarifi - Javad Khoramdel - Yasamin Borhani - Esmaeil Najafi
Graph Attention Networks for Modeling Multi-Sensor Relationships in Early Prediction of Critical Events in ICU Patients
Amir Akhavan Saffar - Danial Eskandari Faruji - Javad Hamidzadeh
Traffic Sign Recognition Using Local Vision Transformer
Ali Farzipour - Omid Nejati Manzari - Shahriar B. Shokouhi
MultiPath ViT OCR: A Lightweight Visual Transformer-based License Plate Optical Character Recognition
Alireza Azadbakht - Saeed Reza Kheradpisheh - Hadi Farahani
Segmentation of Hard Exudates in Retinal Fundus Images Using BCDU-Net
Nafise Ameri - Nasser Shoeibi - Mojtaba Abrishami
Machine and Deep Learning Models for Prediction of Small Molecule–Biotech Drug Pair’s Interactions
Fatemeh Nasiri - Mohsen Hooshmand
Dual-Mode Density-Aware Attention-based Hierarchical Graph Pooling
Roya Booryaee - Parsa Haddadian - Ali Kamandi
Semi-Supervised Supply Chain Fraud Detection with Unsupervised Pre-Filtering
Fatemeh Moradi - Mehran Tarif - Mohammadhossein Homaei
Introducing E4MT and LMBNC: Persian pre-processing utilities
Zakieh Shakeri - Mehran Ziabary - Behrooz Vedadian - Fatemeh Azadi - Saeed Torabzadeh - Arian Atefi
A Genetic-based Fusion Approach of Persian and Universal Phonetic results for Spoken Language Identification
Ashkan Moradi - Yasser Shekofteh - Saeed Zarei
more
Samin Hamayesh - Version 44.5.0