Feature Denoising for Improving Adversarial Robustness

CVPR 2019 Cihang XieYuxin WuLaurens van der MaatenAlan YuilleKaiming He

Adversarial attacks to image classification systems present challenges to convolutional networks and opportunities for understanding them. This study suggests that adversarial perturbations on images lead to noise in the features constructed by these networks... (read more)

PDF Abstract

Evaluation Results from the Paper


TASK DATASET MODEL METRIC NAME METRIC VALUE GLOBAL RANK COMPARE
Adversarial Defense CAAD 2018 Feature Denoising Accuracy 50.6% # 1
Adversarial Defense ImageNet Feature Denoising Accuracy 49.5% # 1