{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/jumprelu-a-retrofit-defense-strategy-for","title":"JumpReLU: A Retrofit Defense Strategy for Adversarial Attacks","arxiv_id":"1904.03750","date":"2019-04-07","proceeding":null,"authors":["N. Benjamin Erichson","Zhewei Yao","Michael W. Mahoney"],"abstract":"It has been demonstrated that very simple attacks can fool\nhighly-sophisticated neural network architectures. In particular, so-called\nadversarial examples, constructed from perturbations of input data that are\nsmall or imperceptible to humans but lead to different predictions, may lead to\nan enormous risk in certain critical applications. In light of this, there has\nbeen a great deal of work on developing adversarial training strategies to\nimprove model robustness. These training strategies are very expensive, in both\nhuman and computational time. To complement these approaches, we propose a very\nsimple and inexpensive strategy which can be used to ``retrofit'' a\npreviously-trained network to improve its resilience to adversarial attacks.\nMore concretely, we propose a new activation function---the JumpReLU---which,\nwhen used in place of a ReLU in an already-trained model, leads to a trade-off\nbetween predictive accuracy and robustness. This trade-off is controlled by the\njump size, a hyper-parameter which can be tuned during the validation stage.\nOur empirical results demonstrate that this increases model robustness,\nprotecting against adversarial attacks with substantially increased levels of\nperturbations. This is accomplished simply by retrofitting existing networks\nwith our JumpReLU activation function, without the need for retraining the\nmodel. Additionally, we demonstrate that adversarially trained (robust) models\ncan greatly benefit from retrofitting.","url_abs":"http://arxiv.org/abs/1904.03750v1","url_pdf":"http://arxiv.org/pdf/1904.03750v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"jumprelu-a-retrofit-defense-strategy-for","repo_url":"https://github.com/erichson/JumpReLU","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[],"methods":[{"method_slug":"relu","method_name":"ReLU"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1904.03750","atlas_url":"https://app.syntology.ai/?focus=1904.03750","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}