{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/defending-against-adversarial-attacks-by-1","title":"Defending against adversarial attacks by randomized diversification","arxiv_id":"1904.00689","date":"2019-04-01","proceeding":"CVPR 2019 6","authors":["Olga Taran","Shideh Rezaeifar","Taras Holotyak","Slava Voloshynovskiy"],"abstract":"The vulnerability of machine learning systems to adversarial attacks\nquestions their usage in many applications. In this paper, we propose a\nrandomized diversification as a defense strategy. We introduce a multi-channel\narchitecture in a gray-box scenario, which assumes that the architecture of the\nclassifier and the training data set are known to the attacker. The attacker\ndoes not only have access to a secret key and to the internal states of the\nsystem at the test time. The defender processes an input in multiple channels.\nEach channel introduces its own randomization in a special transform domain\nbased on a secret key shared between the training and testing stages. Such a\ntransform based randomization with a shared key preserves the gradients in\nkey-defined sub-spaces for the defender but it prevents gradient back\npropagation and the creation of various bypass systems for the attacker. An\nadditional benefit of multi-channel randomization is the aggregation that fuses\nsoft-outputs from all channels, thus increasing the reliability of the final\nscore. The sharing of a secret key creates an information advantage to the\ndefender. Experimental evaluation demonstrates an increased robustness of the\nproposed method to a number of known state-of-the-art attacks.","url_abs":"http://arxiv.org/abs/1904.00689v1","url_pdf":"http://arxiv.org/pdf/1904.00689v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"defending-against-adversarial-attacks-by-1","repo_url":"https://github.com/taranO/defending-adversarial-attacks-by-RD","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"tf","reach":{"status":"ok"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}