{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/hardening-deep-neural-networks-via","title":"Hardening Deep Neural Networks via Adversarial Model Cascades","arxiv_id":"1802.01448","date":"2018-02-02","proceeding":null,"authors":["Deepak Vijaykeerthy","Anshuman Suri","Sameep Mehta","Ponnurangam Kumaraguru"],"abstract":"Deep neural networks (DNNs) are vulnerable to malicious inputs crafted by an\nadversary to produce erroneous outputs. Works on securing neural networks\nagainst adversarial examples achieve high empirical robustness on simple\ndatasets such as MNIST. However, these techniques are inadequate when\nempirically tested on complex data sets such as CIFAR-10 and SVHN. Further,\nexisting techniques are designed to target specific attacks and fail to\ngeneralize across attacks. We propose the Adversarial Model Cascades (AMC) as a\nway to tackle the above inadequacies. Our approach trains a cascade of models\nsequentially where each model is optimized to be robust towards a mixture of\nmultiple attacks. Ultimately, it yields a single model which is secure against\na wide range of attacks; namely FGSM, Elastic, Virtual Adversarial\nPerturbations and Madry. On an average, AMC increases the model's empirical\nrobustness against various attacks simultaneously, by a significant margin (of\n6.225% for MNIST, 5.075% for SVHN and 2.65% for CIFAR10). At the same time, the\nmodel's performance on non-adversarial inputs is comparable to the\nstate-of-the-art models.","url_abs":"http://arxiv.org/abs/1802.01448v4","url_pdf":"http://arxiv.org/pdf/1802.01448v4.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"hardening-deep-neural-networks-via","repo_url":"https://github.com/iamgroot42/Hardening-Deep-Neural-Networks-via-Adversarial-Model-Cascades","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"tf","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}