{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/mitigating-adversarial-effects-through","title":"Mitigating Adversarial Effects Through Randomization","arxiv_id":"1711.01991","date":"2017-11-06","proceeding":"ICLR 2018 1","authors":["Cihang Xie","Jian-Yu Wang","Zhishuai Zhang","Zhou Ren","Alan Yuille"],"abstract":"Convolutional neural networks have demonstrated high accuracy on various\ntasks in recent years. However, they are extremely vulnerable to adversarial\nexamples. For example, imperceptible perturbations added to clean images can\ncause convolutional neural networks to fail. In this paper, we propose to\nutilize randomization at inference time to mitigate adversarial effects.\nSpecifically, we use two randomization operations: random resizing, which\nresizes the input images to a random size, and random padding, which pads zeros\naround the input images in a random manner. Extensive experiments demonstrate\nthat the proposed randomization method is very effective at defending against\nboth single-step and iterative attacks. Our method provides the following\nadvantages: 1) no additional training or fine-tuning, 2) very few additional\ncomputations, 3) compatible with other adversarial defense methods. By\ncombining the proposed randomization method with an adversarially trained\nmodel, it achieves a normalized score of 0.924 (ranked No.2 among 107 defense\nteams) in the NIPS 2017 adversarial examples defense challenge, which is far\nbetter than using adversarial training alone with a normalized score of 0.773\n(ranked No.56). The code is public available at\nhttps://github.com/cihangxie/NIPS2017_adv_challenge_defense.","url_abs":"http://arxiv.org/abs/1711.01991v3","url_pdf":"http://arxiv.org/pdf/1711.01991v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"mitigating-adversarial-effects-through","repo_url":"https://github.com/cihangxie/NIPS2017_adv_challenge_defense","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok","spdx":"MIT"}},{"paper_slug":"mitigating-adversarial-effects-through","repo_url":"https://github.com/cihangxie/DI-2-FGSM","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[{"task_slug":"adversarial-defense","task_name":"Adversarial Defense"},{"task_slug":"image-classification","task_name":"Image Classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1711.01991","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1711.01991"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/cihangxie/DI-2-FGSM","reach":{"status":"ok","spdx":"MIT"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/cihangxie/NIPS2017_adv_challenge_defense","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"unverified":1},"by_repo_kind":{"official":{"samples":1,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"6538fa8b967e8841","entry":"padding_layer_iyswim","repo":"cihangxie/NIPS2017_adv_challenge_defense","repo_kind":"official","path":"defense.py","file_url":"https://github.com/cihangxie/NIPS2017_adv_challenge_defense/blob/HEAD/defense.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"6538fa8b967e8841"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}