{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/improving-adversarial-robustness-of-ensembles","title":"Improving Adversarial Robustness of Ensembles with Diversity Training","arxiv_id":"1901.09981","date":"2019-01-28","proceeding":null,"authors":["Sanjay Kariyappa","Moinuddin K. Qureshi"],"abstract":"Deep Neural Networks are vulnerable to adversarial attacks even in settings\nwhere the attacker has no direct access to the model being attacked. Such\nattacks usually rely on the principle of transferability, whereby an attack\ncrafted on a surrogate model tends to transfer to the target model. We show\nthat an ensemble of models with misaligned loss gradients can provide an\neffective defense against transfer-based attacks. Our key insight is that an\nadversarial example is less likely to fool multiple models in the ensemble if\ntheir loss functions do not increase in a correlated fashion. To this end, we\npropose Diversity Training, a novel method to train an ensemble of models with\nuncorrelated loss functions. We show that our method significantly improves the\nadversarial robustness of ensembles and can also be combined with existing\nmethods to create a stronger defense.","url_abs":"http://arxiv.org/abs/1901.09981v1","url_pdf":"http://arxiv.org/pdf/1901.09981v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"improving-adversarial-robustness-of-ensembles","repo_url":"https://github.com/AI-secure/Transferability-Reduced-Smooth-Ensemble","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-robustness","task_name":"Adversarial Robustness"},{"task_slug":"diversity","task_name":"Diversity"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=1901.09981","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}