{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-and-clean-data-are-not-twins","title":"Adversarial and Clean Data Are Not Twins","arxiv_id":"1704.04960","date":"2017-04-17","proceeding":null,"authors":["Zhitao Gong","Wenlu Wang","Wei-Shinn Ku"],"abstract":"Adversarial attack has cast a shadow on the massive success of deep neural\nnetworks. Despite being almost visually identical to the clean data, the\nadversarial images can fool deep neural networks into wrong predictions with\nvery high confidence. In this paper, however, we show that we can build a\nsimple binary classifier separating the adversarial apart from the clean data\nwith accuracy over 99%. We also empirically show that the binary classifier is\nrobust to a second-round adversarial attack. In other words, it is difficult to\ndisguise adversarial samples to bypass the binary classifier. Further more, we\nempirically investigate the generalization limitation which lingers on all\ncurrent defensive methods, including the binary classifier approach. And we\nhypothesize that this is the result of intrinsic property of adversarial\ncrafting algorithms.","url_abs":"http://arxiv.org/abs/1704.04960v1","url_pdf":"http://arxiv.org/pdf/1704.04960v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-and-clean-data-are-not-twins","repo_url":"https://github.com/gongzhitaao/adversarial-classifier","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1704.04960","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}