论文标题
通过与混乱加密进行的图像denoing的对抗防御
Adversarial Defense via Image Denoising with Chaotic Encryption
论文作者
论文摘要
在有关对抗性例子的文献中,白盒和黑匣子攻击受到了最大的关注。假定对手对防御者的模型具有完整的(白色)或没有(黑色)访问权限。在这项工作中,我们专注于同样实用的灰色框设置,假设攻击者有部分信息。我们提出了一种新颖的防御,假设除了私钥以外的所有东西都将向攻击者提供。我们的框架使用图像Denoising过程,并通过离散的面包师地图加密并加密。针对使用各种梯度制作的对抗图像(例如FGSM,PGD)进行的广泛测试表明,我们的防御能力在CIFAR-10和CIFAR-100上取得了比自然和对抗性精度的最先进的灰色盒子防御能力明显更好。
In the literature on adversarial examples, white box and black box attacks have received the most attention. The adversary is assumed to have either full (white) or no (black) access to the defender's model. In this work, we focus on the equally practical gray box setting, assuming an attacker has partial information. We propose a novel defense that assumes everything but a private key will be made available to the attacker. Our framework uses an image denoising procedure coupled with encryption via a discretized Baker map. Extensive testing against adversarial images (e.g. FGSM, PGD) crafted using various gradients shows that our defense achieves significantly better results on CIFAR-10 and CIFAR-100 than the state-of-the-art gray box defenses in both natural and adversarial accuracy.