Denoising Adversarial Examples Using CNN Models

Juntong Jing · Journal of Physics Conference Series · 2022

Abstract It has always been a complicated problem to resolve adversarial attacks because figures with adversarial attacks look similar to the original figures so that models can be fooled. With deceptive data, adversarial attacks can be a threat to neural networks. There are various ways to generate adversarial attacks. For instance, they are using one-step perturbation and using multi-step perturbation. In both methods, noise is added to the images. Therefore, a question pops up: are adversarial attacks similar to normal random noise? This paper aims to find if there is anything in common between random noise and adversarial attacks. A normal denoising CNN model is trained with random noise. Then groups of adversarial examples are collected by training on LeNet. Next, the denoising CNN model has been used to denoise those adversarial examples. Finally, after denoising the adversarial examples with the CNN model trained on normal random noise, the classification accuracy increases. Thus, it is reasonable to conclude that normal random noise and adversarial tracks have some common patterns.

Read the paper · More papers on PaperTik