{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/magnet-a-two-pronged-defense-against","title":"MagNet: a Two-Pronged Defense against Adversarial Examples","arxiv_id":"1705.09064","date":"2017-05-25","proceeding":null,"authors":["Dongyu Meng","Hao Chen"],"abstract":"Deep learning has shown promising results on hard perceptual problems in\nrecent years. However, deep learning systems are found to be vulnerable to\nsmall adversarial perturbations that are nearly imperceptible to human. Such\nspecially crafted perturbations cause deep learning systems to output incorrect\ndecisions, with potentially disastrous consequences. These vulnerabilities\nhinder the deployment of deep learning systems where safety or security is\nimportant. Attempts to secure deep learning systems either target specific\nattacks or have been shown to be ineffective.\n  In this paper, we propose MagNet, a framework for defending neural network\nclassifiers against adversarial examples. MagNet does not modify the protected\nclassifier or know the process for generating adversarial examples. MagNet\nincludes one or more separate detector networks and a reformer network.\nDifferent from previous work, MagNet learns to differentiate between normal and\nadversarial examples by approximating the manifold of normal examples. Since it\ndoes not rely on any process for generating adversarial examples, it has\nsubstantial generalization power. Moreover, MagNet reconstructs adversarial\nexamples by moving them towards the manifold, which is effective for helping\nclassify adversarial examples with small perturbation correctly. We discuss the\nintrinsic difficulty in defending against whitebox attack and propose a\nmechanism to defend against graybox attack. Inspired by the use of randomness\nin cryptography, we propose to use diversity to strengthen MagNet. We show\nempirically that MagNet is effective against most advanced state-of-the-art\nattacks in blackbox and graybox scenarios while keeping false positive rate on\nnormal examples very low.","url_abs":"http://arxiv.org/abs/1705.09064v2","url_pdf":"http://arxiv.org/pdf/1705.09064v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"magnet-a-two-pronged-defense-against","repo_url":"https://github.com/GokulKarthik/MagNet.pytorch","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"unanswered"}},{"paper_slug":"magnet-a-two-pronged-defense-against","repo_url":"https://github.com/layel2/MagNet-pytorch","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"unanswered"}},{"paper_slug":"magnet-a-two-pronged-defense-against","repo_url":"https://github.com/tommasopuccetti/adversarial_perturbation","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"unanswered"}},{"paper_slug":"magnet-a-two-pronged-defense-against","repo_url":"https://github.com/Trevillie/MagNet","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"tf","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"deep-learning","task_name":"Deep Learning"},{"task_slug":"two","task_name":"Vocal Bursts Valence Prediction"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1705.09064","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}