Engineering Papers⌕ Search

DOE OSTI · 1673321

Probing for Artifacts: Detecting Imagenet Model Evasions

Abstract

While deep learning models have made incredible progress across a variety of machine learning tasks, they remain vulnerable to adversarial examples crafted to fool otherwise trustworthy models. In this work we approach this problem through the lens of a detection framework. We propose a classification network that uses the hidden layer activations of a trained model as inputs to detect adversarial artifacts in an input. We train this classification network simultaneously against multiple adversarial algorithms to create a more robust detector and show higher detection rates than several alternatives. The novelty of our approach is in the scale and scope of probing Imagenet models for adversarial artifacts. In addition, we propose an improvement to feature squeezing, another common adversarial example detection method.

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Rounds, Jeremiah, Kingsland, Addie J., Henry, Michael J., Duskin, Kayla R.. 2020-07-28. Probing for Artifacts: Detecting Imagenet Model Evasions. https://www.osti.gov/biblio/1673321

Cite the original work for its findings. Save a collection to share your selection of sources.