Density Estimation Helps Adversarial Robustness

Afsaneh Hasanebrahimi, Bahareh Kaviani Baghbaderani, Reshad Hosseini, Ahmad Kalhor · 2023

Adversarial attacks pose a threat to deep learning models, as they involve subtle disturbances that are imperceptible to human vision. In this paper, a classification network is introduced that also includes a density estimation head modeled using the decoder of a variational autoencoder. Incorporating the loss of the variational autoencoder during the training of the classifier aids in achieving a robust latent variable. The experimental findings show that the suggested model successfully defends against various gradient-based adversarial attacks, including FGSM, R-FGSM, MI-FGSM, and PGD, in both scenarios involving white-box and black-box contexts.

Read the paper · More papers on PaperTik