Stochastic Activation Pruning for Robust Adversarial Defense

AI-generated keywords: Adversarial Defense Neural Networks Stochastic Activation Pruning (SAP) Game Theory Deep Learning

AI-generated Key Points

The license of the paper does not allow us to build upon its content and the key points are generated using the paper metadata rather than the full article.

  • Neural networks vulnerable to adversarial examples
  • Adversarial examples undermine reliability of deep learning systems
  • Problem framed as minimax zero-sum game between adversary and model
  • Proposed solution: Stochastic Activation Pruning (SAP)
  • SAP involves randomly pruning subset of activations with preference for smaller magnitudes, scaling up remaining activations
  • SAP can be applied to pretrained networks without fine-tuning
  • Experimental results show SAP improves robustness against attacks, enhances accuracy, preserves calibration
  • SAP provides effective defense mechanism against adversarial examples in deep learning systems
Also access our AI generated: Comprehensive summary, Lay summary, Blog-like article; or ask questions about this paper to our AI assistant.

Authors: Guneet S. Dhillon, Kamyar Azizzadenesheli, Zachary C. Lipton, Jeremy Bernstein, Jean Kossaifi, Aran Khanna, Anima Anandkumar

ICLR 2018

Abstract: Neural networks are known to be vulnerable to adversarial examples. Carefully chosen perturbations to real images, while imperceptible to humans, induce misclassification and threaten the reliability of deep learning systems in the wild. To guard against adversarial examples, we take inspiration from game theory and cast the problem as a minimax zero-sum game between the adversary and the model. In general, for such games, the optimal strategy for both players requires a stochastic policy, also known as a mixed strategy. In this light, we propose Stochastic Activation Pruning (SAP), a mixed strategy for adversarial defense. SAP prunes a random subset of activations (preferentially pruning those with smaller magnitude) and scales up the survivors to compensate. We can apply SAP to pretrained networks, including adversarially trained models, without fine-tuning, providing robustness against adversarial examples. Experiments demonstrate that SAP confers robustness against attacks, increasing accuracy and preserving calibration.

Submitted to arXiv on 05 Mar. 2018

Ask questions about this paper to our AI assistant

You can also chat with multiple papers at once here.

The license of the paper does not allow us to build upon its content and the AI assistant only knows about the paper metadata rather than the full article.

AI assistant instructions?

Results of the summarizing process for the arXiv paper: 1803.01442v1

This paper's license doesn't allow us to build upon its content and the summarizing process is here made with the paper's metadata rather than the article.

Neural networks have been shown to be vulnerable to adversarial examples, where carefully crafted perturbations of real images can lead to misclassification and undermine the reliability of deep learning systems. To address this issue, the authors draw inspiration from game theory and frame the problem as a minimax zero-sum game between the adversary and the model. They propose a mixed strategy called Stochastic Activation Pruning (SAP) for robust adversarial defense. SAP involves randomly pruning a subset of activations with preference for those with smaller magnitudes while scaling up the remaining activations to compensate. The advantage of SAP is that it can be applied to pretrained networks including adversarially trained models without requiring fine-tuning. Experimental results demonstrate that SAP improves robustness against attacks by enhancing accuracy and preserving calibration. This approach provides an effective defense mechanism against adversarial examples in deep learning systems.
Created on 18 Nov. 2023

Assess the quality of the AI-generated content by voting

Score: 0

Why do we need votes?

Votes are used to determine whether we need to re-run our summarizing tools. If the count reaches -10, our tools can be restarted.

The previous summary was created more than a year ago and can be re-run (if necessary) by clicking on the Run button below.

The license of this specific paper does not allow us to build upon its content and the summarizing tools will be run using the paper metadata rather than the full article. However, it still does a good job, and you can also try our tools on papers with more open licenses.

Similar papers summarized with our AI tools

Navigate through even more similar papers through a

tree representation

Look for similar papers (in beta version)

By clicking on the button above, our algorithm will scan all papers in our database to find the closest based on the contents of the full papers and not just on metadata. Please note that it only works for papers that we have generated summaries for and you can rerun it from time to time to get a more accurate result while our database grows.

Disclaimer: The AI-based summarization tool and virtual assistant provided on this website may not always provide accurate and complete summaries or responses. We encourage you to carefully review and evaluate the generated content to ensure its quality and relevance to your needs.