Papers › Mitigating large adversarial perturbations on X-MAS (X minus Moving Averaged Samples)
Mitigating large adversarial perturbations on X-MAS (X minus Moving Averaged Samples)
Woohyung Chun, Sung-Min Hong, Junho Huh, Inyup Kang
We propose the scheme that mitigates the adversarial perturbation ϵ on the adversarial example X_(adv) (= X ± ϵ, X is a benign sample) by subtracting the estimated perturbation ϵ̂ from X + ϵ and adding ϵ̂ to X - ϵ. The estimated perturbation ϵ̂ comes from the difference between X_(adv) and its moving-averaged outcome W_(avg)*X_(adv) where W_(avg) is N ×N moving average kernel that all the coefficients are one. Usually, the adjacent samples of an image are close to each other such that we can let X ≈ W_(avg)*X (naming this relation after X-MAS[X minus Moving Averaged Samples]). By doing that, we can make the estimated perturbation ϵ̂ falls within the range of ϵ. The scheme is also extended to do the multi-level mitigation by configuring the mitigated adversarial example X_(adv) ± ϵ̂ as a new adversarial example to be mitigated. The multi-level mitigation gets X_(adv) closer to X with a smaller (i.e. mitigated) perturbation than original unmitigated perturbation by setting the moving averaged adversarial sample W_(avg) * X_(adv) (which has the smaller perturbation than X_(adv) if X ≈ W_(avg)*X) as the boundary condition that the multi-level mitigation cannot cross over (i.e. decreasing ϵ cannot go below and increasing ϵ cannot go beyond). With the multi-level mitigation, we can get high prediction accuracies even in the adversarial example having a large perturbation (i.e. ϵ > $16$). The proposed scheme is evaluated with adversarial examples crafted by the FGSM (Fast Gradient Sign Method) based attacks on ResNet-50 trained with ImageNet dataset.
Code
Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.
Code Syntology ran Syntology
Not run by Syntology. Nothing on this page verifies that the listed code works.
Results from the paper archive 2025-07-28
No leaderboard rows for this paper in the archive.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections