arXiv · 2002.09580
Polarizing Front Ends for Robust CNNs
Abstract
The vulnerability of deep neural networks to small, adversarially designed perturbations can be attributed to their "excessive linearity." In this paper, we propose a bottom-up strategy for attenuating adversarial perturbations using a nonlinear front end which polarizes and quantizes the data. We observe that ideal polarization can be utilized to completely eliminate perturbations, develop algorithms to learn approximately polarizing bases for data, and investigate the effectiveness of the proposed strategy on the MNIST and Fashion MNIST datasets.
Explore related subjects
Keep this discovery
Can Bakiskan, Soorya Gopalakrishnan, Metehan Cekic, Upamanyu Madhow, Ramtin Pedarsani. 2020-02-22. Polarizing Front Ends for Robust CNNs. https://arxiv.org/abs/2002.09580
Cite the original work for its findings. Save a collection to share your selection of sources.