arXiv · 1705.05264
Extending Defensive Distillation
Abstract
Machine learning is vulnerable to adversarial examples: inputs carefully modified to force misclassification. Designing defenses against such inputs remains largely an open problem. In this work, we revisit defensive distillation---which is one of the mechanisms proposed to mitigate adversarial examples---to address its limitations. We view our results not only as an effective way of addressing some of the recently discovered attacks but also as reinforcing the importance of improved training techniques.
Explore related subjects
Keep this discovery
Nicolas Papernot, Patrick McDaniel. 2017-05-15. Extending Defensive Distillation. https://arxiv.org/abs/1705.05264
Cite the original work for its findings. Save a collection to share your selection of sources.