preprintJun 18, 2023GOLD OA

Adversarial and Clean Data Are Not Twins

Auburn University · Texas A&M University – Corpus Christi

Indexed incrossref

Abstract

Adversarial attack has cast a shadow on the massive success of deep neural networks. Despite being almost visually identical to the clean data, the adversarial images can fool deep neural networks into the wrong predictions with very high confidence. Adversarial training, as the most prevailing defense technique, suffers from class-wise unfairness and model-dependent challenges. In this paper, we propose to detect and eliminate adversarial data in databases prior to data processing in supporting robust and secure AI workloads. We empirically show that we can build a binary classifier separating the adversarial apart from the clean data with high accuracy. We also show that the binary classifier is robust to a…

Citation impact

190
total citations
FWCI
6.31
Percentile
100%
References
9
Citations per year

Authors

2

Topics & keywords

Keywords
  • Adversarial system
  • Computer science
  • Classifier (UML)
  • Artificial intelligence
  • Binary classification
  • Binary number
  • Deep neural networks
  • Machine learning
No related works found for this paper.