MagNet with Randomization Defense against Adversarial Examples
Fangwei Wang, Guofang Chai, Qingru Li, Changguang Wang · 2020
With the development of the neural networks, deep learning has achieved advanced performance in various tasks. In recent years, however, researchers have found that Convolutional Neural Networks (CNNs) were vulnerable to adversarial examples-adding imperceptible perturbations to the original images can cause misclassification. This paper proposes a new defense method against adversarial examples attack. Based on the defense strategy of the MagNet, we add two random layers: one is used to randomly adjust the image size and the other is used to randomly fill the image with zero to reduce the impact of adversarial attack. Our method provides the following advantages: 1)The framework does not rely on adversarial examples and its generation process. 2)The method is relatively easy and effective in practice. The experiment results show that this method not only can effectively defend the common attack but also the overall accuracy is 3% higher than MagNet.