{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/defense-against-adversarial-attacks-using","title":"Defense against Adversarial Attacks Using High-Level Representation Guided Denoiser","arxiv_id":"1712.02976","date":"2017-12-08","proceeding":"CVPR 2018 6","authors":["Fangzhou Liao","Ming Liang","Yinpeng Dong","Tianyu Pang","Xiaolin Hu","Jun Zhu"],"abstract":"Neural networks are vulnerable to adversarial examples, which poses a threat\nto their application in security sensitive systems. We propose high-level\nrepresentation guided denoiser (HGD) as a defense for image classification.\nStandard denoiser suffers from the error amplification effect, in which small\nresidual adversarial noise is progressively amplified and leads to wrong\nclassifications. HGD overcomes this problem by using a loss function defined as\nthe difference between the target model's outputs activated by the clean image\nand denoised image. Compared with ensemble adversarial training which is the\nstate-of-the-art defending method on large images, HGD has three advantages.\nFirst, with HGD as a defense, the target model is more robust to either\nwhite-box or black-box adversarial attacks. Second, HGD can be trained on a\nsmall subset of the images and generalizes well to other images and unseen\nclasses. Third, HGD can be transferred to defend models other than the one\nguiding it. In NIPS competition on defense against adversarial attacks, our HGD\nsolution won the first place and outperformed other models by a large margin.","url_abs":"http://arxiv.org/abs/1712.02976v2","url_pdf":"http://arxiv.org/pdf/1712.02976v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"defense-against-adversarial-attacks-using","repo_url":"https://github.com/lfz/Guided-Denoise","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":{"status":"unanswered"}},{"paper_slug":"defense-against-adversarial-attacks-using","repo_url":"https://github.com/anishathalye/Guided-Denoise","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"adversarial-defense","task_name":"Adversarial Defense"},{"task_slug":"image-classification","task_name":"Image Classification"},{"task_slug":"high","task_name":"Vocal Bursts Intensity Prediction"},{"task_slug":"image-classification","task_name":"image-classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1712.02976","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}