{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adv-bnn-improved-adversarial-defense-through","title":"Adv-BNN: Improved Adversarial Defense through Robust Bayesian Neural Network","arxiv_id":"1810.01279","date":"2018-10-01","proceeding":"ICLR 2019 5","authors":["Xuanqing Liu","Yao Li","Chongruo wu","Cho-Jui Hsieh"],"abstract":"We present a new algorithm to train a robust neural network against adversarial attacks. Our algorithm is motivated by the following two ideas. First, although recent work has demonstrated that fusing randomness can improve the robustness of neural networks (Liu 2017), we noticed that adding noise blindly to all the layers is not the optimal way to incorporate randomness. Instead, we model randomness under the framework of Bayesian Neural Network (BNN) to formally learn the posterior distribution of models in a scalable way. Second, we formulate the mini-max problem in BNN to learn the best model distribution under adversarial attacks, leading to an adversarial-trained Bayesian neural net. Experiment results demonstrate that the proposed algorithm achieves state-of-the-art performance under strong attacks. On CIFAR-10 with VGG network, our model leads to 14\\% accuracy improvement compared with adversarial training (Madry 2017) and random self-ensemble (Liu 2017) under PGD attack with $0.035$ distortion, and the gap becomes even larger on a subset of ImageNet.","url_abs":"https://arxiv.org/abs/1810.01279v2","url_pdf":"https://arxiv.org/pdf/1810.01279v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adv-bnn-improved-adversarial-defense-through","repo_url":"https://github.com/xuanqing94/BayesianDefense","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[{"task_slug":"adversarial-defense","task_name":"Adversarial Defense"}],"methods":[{"method_slug":"convolution","method_name":"Convolution"},{"method_slug":"dense-connections","method_name":"Dense Connections"},{"method_slug":"dropout","method_name":"Dropout"},{"method_slug":"max-pooling","method_name":"Max Pooling"},{"method_slug":"relu","method_name":"ReLU"},{"method_slug":"softmax","method_name":"Softmax"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1810.01279","atlas_url":"https://app.syntology.ai/?focus=1810.01279","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1810.01279"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/xuanqing94/BayesianDefense","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"unverified":4},"by_repo_kind":{"official":{"samples":4,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"995b6550b7810165","entry":"distance","repo":"xuanqing94/BayesianDefense","repo_kind":"official","path":"acc_under_attack.py","file_url":"https://github.com/xuanqing94/BayesianDefense/blob/HEAD/acc_under_attack.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"995b6550b7810165"}},{"code_sha256_prefix":"c3d19147a0078100","entry":"ensemble_inference","repo":"xuanqing94/BayesianDefense","repo_kind":"official","path":"acc_under_attack.py","file_url":"https://github.com/xuanqing94/BayesianDefense/blob/HEAD/acc_under_attack.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"c3d19147a0078100"}},{"code_sha256_prefix":"1f144f38f1f9690a","entry":"get_beta","repo":"xuanqing94/BayesianDefense","repo_kind":"official","path":"main_adv_vi.py","file_url":"https://github.com/xuanqing94/BayesianDefense/blob/HEAD/main_adv_vi.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"1f144f38f1f9690a"}},{"code_sha256_prefix":"d6455c16838870db","entry":"get_beta","repo":"xuanqing94/BayesianDefense","repo_kind":"official","path":"main_vi.py","file_url":"https://github.com/xuanqing94/BayesianDefense/blob/HEAD/main_vi.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"d6455c16838870db"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}