Matches in SemOpenAlex for { <https://semopenalex.org/work/W4360889968> ?p ?o ?g. }
Showing items 1 to 67 of
67
with 100 items per page.
- W4360889968 abstract "Training-time defenses, known as adversarial training, incur high training costs and do not generalize to unseen attacks. Test-time defenses solve these issues but most existing test-time defenses require adapting the model weights, therefore they do not work on frozen models and complicate model memory management. The only test-time defense that does not adapt model weights aims to adapt the input with self-supervision tasks. However, we empirically found these self-supervision tasks are not sensitive enough to detect adversarial attacks accurately. In this paper, we propose DRAM, a novel defense method to detect and repair adversarial samples at test time via Masked autoencoder (MAE). We demonstrate how to use MAE losses to build a Kolmogorov-Smirnov test to detect adversarial samples. Moreover, we use the MAE losses to calculate input reversal vectors that repair adversarial samples resulting from previously unseen attacks. Results on large-scale ImageNet dataset show that, compared to all detection baselines evaluated, DRAM achieves the best detection rate (82% on average) on all eight adversarial attacks evaluated. For attack repair, DRAM improves the robust accuracy by 6% ~ 41% for standard ResNet50 and 3% ~ 8% for robust ResNet50 compared with the baselines that use contrastive learning and rotation prediction." @default.
- W4360889968 created "2023-03-25" @default.
- W4360889968 creator A5005107485 @default.
- W4360889968 creator A5039055847 @default.
- W4360889968 creator A5042351717 @default.
- W4360889968 creator A5056835845 @default.
- W4360889968 creator A5059677431 @default.
- W4360889968 creator A5061451821 @default.
- W4360889968 creator A5072154724 @default.
- W4360889968 date "2023-03-22" @default.
- W4360889968 modified "2023-10-14" @default.
- W4360889968 title "Test-time Detection and Repair of Adversarial Samples via Masked Autoencoder" @default.
- W4360889968 doi "https://doi.org/10.48550/arxiv.2303.12848" @default.
- W4360889968 hasPublicationYear "2023" @default.
- W4360889968 type Work @default.
- W4360889968 citedByCount "0" @default.
- W4360889968 crossrefType "posted-content" @default.
- W4360889968 hasAuthorship W4360889968A5005107485 @default.
- W4360889968 hasAuthorship W4360889968A5039055847 @default.
- W4360889968 hasAuthorship W4360889968A5042351717 @default.
- W4360889968 hasAuthorship W4360889968A5056835845 @default.
- W4360889968 hasAuthorship W4360889968A5059677431 @default.
- W4360889968 hasAuthorship W4360889968A5061451821 @default.
- W4360889968 hasAuthorship W4360889968A5072154724 @default.
- W4360889968 hasBestOaLocation W43608899681 @default.
- W4360889968 hasConcept C101738243 @default.
- W4360889968 hasConcept C108583219 @default.
- W4360889968 hasConcept C119857082 @default.
- W4360889968 hasConcept C151730666 @default.
- W4360889968 hasConcept C154945302 @default.
- W4360889968 hasConcept C199360897 @default.
- W4360889968 hasConcept C2777267654 @default.
- W4360889968 hasConcept C2781215313 @default.
- W4360889968 hasConcept C37736160 @default.
- W4360889968 hasConcept C41008148 @default.
- W4360889968 hasConcept C7366592 @default.
- W4360889968 hasConcept C86803240 @default.
- W4360889968 hasConcept C9390403 @default.
- W4360889968 hasConceptScore W4360889968C101738243 @default.
- W4360889968 hasConceptScore W4360889968C108583219 @default.
- W4360889968 hasConceptScore W4360889968C119857082 @default.
- W4360889968 hasConceptScore W4360889968C151730666 @default.
- W4360889968 hasConceptScore W4360889968C154945302 @default.
- W4360889968 hasConceptScore W4360889968C199360897 @default.
- W4360889968 hasConceptScore W4360889968C2777267654 @default.
- W4360889968 hasConceptScore W4360889968C2781215313 @default.
- W4360889968 hasConceptScore W4360889968C37736160 @default.
- W4360889968 hasConceptScore W4360889968C41008148 @default.
- W4360889968 hasConceptScore W4360889968C7366592 @default.
- W4360889968 hasConceptScore W4360889968C86803240 @default.
- W4360889968 hasConceptScore W4360889968C9390403 @default.
- W4360889968 hasLocation W43608899681 @default.
- W4360889968 hasOpenAccess W4360889968 @default.
- W4360889968 hasPrimaryLocation W43608899681 @default.
- W4360889968 hasRelatedWork W2567271240 @default.
- W4360889968 hasRelatedWork W2788487394 @default.
- W4360889968 hasRelatedWork W2904372345 @default.
- W4360889968 hasRelatedWork W2922457425 @default.
- W4360889968 hasRelatedWork W2989980351 @default.
- W4360889968 hasRelatedWork W3002526821 @default.
- W4360889968 hasRelatedWork W3044458868 @default.
- W4360889968 hasRelatedWork W4213225422 @default.
- W4360889968 hasRelatedWork W4250304930 @default.
- W4360889968 hasRelatedWork W4289656111 @default.
- W4360889968 isParatext "false" @default.
- W4360889968 isRetracted "false" @default.
- W4360889968 workType "article" @default.