BriefGPT.xyz
Sep, 2020
鲁棒性的来源在哪里?基于转换的集成防御研究
Where Does the Robustness Come from? A Study of the Transformation-based Ensemble Defence
HTML
PDF
Chang Liao, Yao Cheng, Chengfang Fang, Jie Shi
TL;DR
通过研究变换式集成防御在图像分类中的有效性和原因,本文设计两种自适应攻击方法,揭示了对抗样本传递性的存在,变换式集成防御的鲁棒性收益受到限制,而这种限制主要来自于不可逆变换而非模型集成。
Abstract
This paper aims to provide a thorough study on the effectiveness of the transformation-based ensemble defence for
image classification
and its reasons. It has been empirically shown that they can enhance the
robustness<
→