Transferable Adversarial Robustness using Adversarially Trained Autoencoders.
P. Vaishnavi, Kevin Eykholt, Atul Prakash, Amir Rahmati · arXiv (Cornell University) · 2019
Adversarial machine learning is a well-studied field of research where an adversary causes predictable errors in a machine learning algorithm through careful manipulation of the input. Numerous techniques have been proposed to harden machine learning algorithms and mitigate the effect of adversarial attacks. Of these techniques, adversarial training, which augments the training data with adversarial samples, has proven to be an effective defensive technique with respect to a certain class of attacks. However, adversarial training is computationally expensive and its improvements are limited to a single classifier. In this paper, we propose Adversarially-Trained Autoencoder Augmentation, the first transferable adversarial defense that is robust to certain adaptive adversaries. We disentangle adversarial robustness from the classification pipeline by adversarially training an autoencoder with respect to the classification loss of a naturally trained classifier. The main advantage of our work is that the autoencoders can be reused to protect other vulnerable classifiers without additional training. We show that our approach improves the adversarial robustness of a naturally trained classifier by at least 45\% in MNIST and Fashion-MNIST datasets despite no additional training. On CIFAR-10, we can train a single autoencoder to protect multiple naturally trained classifiers and achieve adversarial performance on par or better than adversarial training. Finally, using a natural image corruption dataset, we show that our approach improves robustness to naturally corrupted images, which has been identified as strongly indicative of true adversarial robustness.