{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/puvae-a-variational-autoencoder-to-purify","title":"PuVAE: A Variational Autoencoder to Purify Adversarial Examples","arxiv_id":"1903.00585","date":"2019-03-02","proceeding":null,"authors":["Uiwon Hwang","Jaewoo Park","Hyemi Jang","Sungroh Yoon","Nam Ik Cho"],"abstract":"Deep neural networks are widely used and exhibit excellent performance in\nmany areas. However, they are vulnerable to adversarial attacks that compromise\nthe network at the inference time by applying elaborately designed perturbation\nto input data. Although several defense methods have been proposed to address\nspecific attacks, other attack methods can circumvent these defense mechanisms.\nTherefore, we propose Purifying Variational Autoencoder (PuVAE), a method to\npurify adversarial examples. The proposed method eliminates an adversarial\nperturbation by projecting an adversarial example on the manifold of each\nclass, and determines the closest projection as a purified sample. We\nexperimentally illustrate the robustness of PuVAE against various attack\nmethods without any prior knowledge. In our experiments, the proposed method\nexhibits performances competitive with state-of-the-art defense methods, and\nthe inference time is approximately 130 times faster than that of Defense-GAN\nthat is the state-of-the art purifier model.","url_abs":"http://arxiv.org/abs/1903.00585v1","url_pdf":"http://arxiv.org/pdf/1903.00585v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[],"tasks":[{"task_slug":"adversarial-defense","task_name":"Adversarial Defense"},{"task_slug":"adversarial-defense-against-fgsm-attack","task_name":"Adversarial Defense against FGSM Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[{"leaderboard":"/sota/adversarial-defense-on-mnist","task":"Adversarial Defense","dataset":"MNIST","model":"PuVAE","rank_in_archive_order":2,"of":2,"metrics":{"Accuracy":"0.8133","Inference speed":"0.11"},"uses_additional_data":false}],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1903.00585","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}