DOE OSTI · 1673321
Probing for Artifacts: Detecting Imagenet Model Evasions
Abstract
While deep learning models have made incredible progress across a variety of machine learning tasks, they remain vulnerable to adversarial examples crafted to fool otherwise trustworthy models. In this work we approach this problem through the lens of a detection framework. We propose a classification network that uses the hidden layer activations of a trained model as inputs to detect adversarial artifacts in an input. We train this classification network simultaneously against multiple adversarial algorithms to create a more robust detector and show higher detection rates than several alternatives. The novelty of our approach is in the scale and scope of probing Imagenet models for adversarial artifacts. In addition, we propose an improvement to feature squeezing, another common adversarial example detection method.
Keep this discovery
Explore connections, maps & timelines
Rounds, Jeremiah, Kingsland, Addie J., Henry, Michael J., Duskin, Kayla R.. 2020-07-28. Probing for Artifacts: Detecting Imagenet Model Evasions. https://www.osti.gov/biblio/1673321
Cite the original work for its findings. Save a collection to share your selection of sources.