Adversarial Training against Location-Optimized Adversarial Patches

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Rao, Sukrut, Stutz, David, Schiele, Bernt
Format: Preprint
Published: 2020
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917728055459840
author Rao, Sukrut
Stutz, David
Schiele, Bernt
author_facet Rao, Sukrut
Stutz, David
Schiele, Bernt
contents Deep neural networks have been shown to be susceptible to adversarial examples -- small, imperceptible changes constructed to cause mis-classification in otherwise highly accurate image classifiers. As a practical alternative, recent work proposed so-called adversarial patches: clearly visible, but adversarially crafted rectangular patches in images. These patches can easily be printed and applied in the physical world. While defenses against imperceptible adversarial examples have been studied extensively, robustness against adversarial patches is poorly understood. In this work, we first devise a practical approach to obtain adversarial patches while actively optimizing their location within the image. Then, we apply adversarial training on these location-optimized adversarial patches and demonstrate significantly improved robustness on CIFAR10 and GTSRB. Additionally, in contrast to adversarial training on imperceptible adversarial examples, our adversarial patch training does not reduce accuracy.
format Preprint
id arxiv_https___arxiv_org_abs_2005_02313
institution arXiv
publishDate 2020
record_format arxiv
spellingShingle Adversarial Training against Location-Optimized Adversarial Patches
Rao, Sukrut
Stutz, David
Schiele, Bernt
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
Deep neural networks have been shown to be susceptible to adversarial examples -- small, imperceptible changes constructed to cause mis-classification in otherwise highly accurate image classifiers. As a practical alternative, recent work proposed so-called adversarial patches: clearly visible, but adversarially crafted rectangular patches in images. These patches can easily be printed and applied in the physical world. While defenses against imperceptible adversarial examples have been studied extensively, robustness against adversarial patches is poorly understood. In this work, we first devise a practical approach to obtain adversarial patches while actively optimizing their location within the image. Then, we apply adversarial training on these location-optimized adversarial patches and demonstrate significantly improved robustness on CIFAR10 and GTSRB. Additionally, in contrast to adversarial training on imperceptible adversarial examples, our adversarial patch training does not reduce accuracy.
title Adversarial Training against Location-Optimized Adversarial Patches
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2005.02313