Adversarial Example Defense Based on the Supervision

Ziyu Yao, Jiaquan Gao · 2021

In recent years, deep learning has developed rapidly and has shown great performance on many challenging machine learning tasks, such as image classification, natural language processing, and speech recognition. However, researchers have recently discovered that deep learning models have security risks and are easily affected by adversarial examples. The adversarial example is a sample formed by deliberately adding subtle perturbation that is invisible to the human in the dataset. It can make the classification classify incorrectly with a high degree of confidence, which poses more challenges for deep learning research. In this paper, we propose a defense model based on the supervision mechanism. The model adds supervision layers to the original convolutional neural network and improves the robustness and defense ability of the model by improving the loss function. The LeNet-5 and VGG networks are used as the original network models. The experimental results on MNIST and CIFAR-10 confirm that the method proposed in this paper will effectively increase the difficulty of the attackers.

Read the paper · More papers on PaperTik