Timezone: »
Deep neural networks are vulnerable to adversarial attacks. The literature is rich with algorithms that can easily craft successful adversarial examples. In contrast, the performance of defense techniques still lags behind. This paper proposes ME-Net, a defense method that leverages matrix estimation (ME). In ME-Net, images are preprocessed using two steps: first pixels are randomly dropped from the image; then, the image is reconstructed using ME. We show that this process destroys the adversarial structure of the noise, while re-enforcing the global structure in the original image. Since humans typically rely on such global structures in classifying images, the process makes the network mode compatible with human perception. We conduct comprehensive experiments on prevailing benchmarks such as MNIST, CIFAR-10, SVHN, and Tiny-ImageNet. Comparing ME-Net with state-of-the-art defense mechanisms shows that ME-Net consistently outperforms prior techniques, improving robustness against both black-box and white-box attacks.
Author Information
Yuzhe Yang (MIT)
GUO ZHANG (MIT)
Zhi Xu (MIT)
Dina Katabi (MIT)
Related Events (a corresponding poster, oral, or spotlight)
-
2019 Poster: ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation »
Thu. Jun 13th 01:30 -- 04:00 AM Room Pacific Ballroom #63
More from the Same Authors
-
2023 Workshop: 3rd Workshop on Interpretable Machine Learning in Healthcare (IMLH) »
Weina Jin · Ramin Zabih · S. Kevin Zhou · Yuyin Zhou · Xiaoxiao Li · Yifan Peng · Zongwei Zhou · Yucheng Tang · Yuzhe Yang · Agni Kumar -
2023 Poster: Change is Hard: A Closer Look at Subpopulation Shift »
Yuzhe Yang · Haoran Zhang · Dina Katabi · Marzyeh Ghassemi -
2021 Poster: Delving into Deep Imbalanced Regression »
Yuzhe Yang · Kaiwen Zha · YINGCONG CHEN · Hao Wang · Dina Katabi -
2021 Oral: Delving into Deep Imbalanced Regression »
Yuzhe Yang · Kaiwen Zha · YINGCONG CHEN · Hao Wang · Dina Katabi -
2020 Poster: Continuously Indexed Domain Adaptation »
Hao Wang · Hao He · Dina Katabi -
2019 Poster: Circuit-GNN: Graph Neural Networks for Distributed Circuit Design »
GUO ZHANG · Hao He · Dina Katabi -
2019 Oral: Circuit-GNN: Graph Neural Networks for Distributed Circuit Design »
GUO ZHANG · Hao He · Dina Katabi -
2017 Poster: Learning Sleep Stages from Radio Signals: A Conditional Adversarial Architecture »
Mingmin Zhao · Shichao Yue · Dina Katabi · Tommi Jaakkola · Matt Bianchi -
2017 Talk: Learning Sleep Stages from Radio Signals: A Conditional Adversarial Architecture »
Mingmin Zhao · Shichao Yue · Dina Katabi · Tommi Jaakkola · Matt Bianchi