{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/deflecting-adversarial-attacks-with-pixel","title":"Deflecting Adversarial Attacks with Pixel Deflection","arxiv_id":"1801.08926","date":"2018-01-26","proceeding":"CVPR 2018 6","authors":["Aaditya Prakash","Nick Moran","Solomon Garber","Antonella DiLillo","James Storer"],"abstract":"CNNs are poised to become integral parts of many critical systems. Despite\ntheir robustness to natural variations, image pixel values can be manipulated,\nvia small, carefully crafted, imperceptible perturbations, to cause a model to\nmisclassify images. We present an algorithm to process an image so that\nclassification accuracy is significantly preserved in the presence of such\nadversarial manipulations. Image classifiers tend to be robust to natural\nnoise, and adversarial attacks tend to be agnostic to object location. These\nobservations motivate our strategy, which leverages model robustness to defend\nagainst adversarial perturbations by forcing the image to match natural image\nstatistics. Our algorithm locally corrupts the image by redistributing pixel\nvalues via a process we term pixel deflection. A subsequent wavelet-based\ndenoising operation softens this corruption, as well as some of the adversarial\nchanges. We demonstrate experimentally that the combination of these techniques\nenables the effective recovery of the true class, against a variety of robust\nattacks. Our results compare favorably with current state-of-the-art defenses,\nwithout requiring retraining or modifying the CNN.","url_abs":"http://arxiv.org/abs/1801.08926v3","url_pdf":"http://arxiv.org/pdf/1801.08926v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"deflecting-adversarial-attacks-with-pixel","repo_url":"https://github.com/iamaaditya/pixel-deflection","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"none","reach":{"status":"unanswered"}},{"paper_slug":"deflecting-adversarial-attacks-with-pixel","repo_url":"https://github.com/anishathalye/pixel-deflection","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"unanswered"}},{"paper_slug":"deflecting-adversarial-attacks-with-pixel","repo_url":"https://github.com/carlini/pixel-deflection","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=1801.08926","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}