{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-defense-of-image-classification","title":"Adversarial Defense of Image Classification Using a Variational Auto-Encoder","arxiv_id":"1812.02891","date":"2018-12-07","proceeding":null,"authors":["Yi Luo","Henry Pfister"],"abstract":"Deep neural networks are known to be vulnerable to adversarial attacks. This\nexposes them to potential exploits in security-sensitive applications and\nhighlights their lack of robustness. This paper uses a variational auto-encoder\n(VAE) to defend against adversarial attacks for image classification tasks.\nThis VAE defense has a few nice properties: (1) it is quite flexible and its\nuse of randomness makes it harder to attack; (2) it can learn disentangled\nrepresentations that prevent blurry reconstruction; and (3) a patch-wise VAE\ndefense strategy is used that does not require retraining for different size\nimages. For moderate to severe attacks, this system outperforms or closely\nmatches the performance of JPEG compression, with the best quality parameter.\nIt also has more flexibility and potential for improvement via training.","url_abs":"http://arxiv.org/abs/1812.02891v1","url_pdf":"http://arxiv.org/pdf/1812.02891v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-defense-of-image-classification","repo_url":"https://github.com/Roy-YL/VAE-Adversarial-Defense","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":null}],"tasks":[{"task_slug":"adversarial-defense","task_name":"Adversarial Defense"},{"task_slug":"classification","task_name":"General Classification"},{"task_slug":"image-classification","task_name":"Image Classification"},{"task_slug":"image-classification","task_name":"image-classification"}],"methods":[{"method_slug":"affine-coupling","method_name":"Affine Coupling"},{"method_slug":"normalizing-flows","method_name":"Normalizing Flows"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}