{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/countering-adversarial-images-using-input","title":"Countering Adversarial Images using Input Transformations","arxiv_id":"1711.00117","date":"2017-10-31","proceeding":"ICLR 2018 1","authors":["Chuan Guo","Mayank Rana","Moustapha Cisse","Laurens van der Maaten"],"abstract":"This paper investigates strategies that defend against adversarial-example\nattacks on image-classification systems by transforming the inputs before\nfeeding them to the system. Specifically, we study applying image\ntransformations such as bit-depth reduction, JPEG compression, total variance\nminimization, and image quilting before feeding the image to a convolutional\nnetwork classifier. Our experiments on ImageNet show that total variance\nminimization and image quilting are very effective defenses in practice, in\nparticular, when the network is trained on transformed images. The strength of\nthose defenses lies in their non-differentiable nature and their inherent\nrandomness, which makes it difficult for an adversary to circumvent the\ndefenses. Our best defense eliminates 60% of strong gray-box and 90% of strong\nblack-box attacks by a variety of major attack methods","url_abs":"http://arxiv.org/abs/1711.00117v3","url_pdf":"http://arxiv.org/pdf/1711.00117v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"countering-adversarial-images-using-input","repo_url":"https://github.com/facebookresearch/adversarial_image_defenses","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"NOASSERTION"}}],"tasks":[{"task_slug":"adversarial-defense","task_name":"Adversarial Defense"},{"task_slug":"classification","task_name":"General Classification"},{"task_slug":"image-classification","task_name":"Image Classification"},{"task_slug":"image-classification","task_name":"image-classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1711.00117","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}