Improving the robustness of neural networks using k-support norm based adversarial training

Akhtar, Sheikh Waqas, Rehman, Saad, Akhtar, Mahmood , Khan, Muazzam A, Riaz, Farhan, Chaudry, Qaiser and Young, Rupert (2017) Improving the robustness of neural networks using k-support norm based adversarial training. IEEE Access, 4 . pp. 9501-9511. ISSN 2169-3536

Full content URL: https://doi.org/10.1109/ACCESS.2016.2643678

Documents
Improving the robustness of neural networks using k-support norm based adversarial training
Open access published manuscript
[img]
[Download]
[img]
Preview
PDF
Improving_the_Robustness_of_Neural_Networks_Using_K-Support_Norm_Based_Adversarial_Training.pdf - Whole Document
Available under License Creative Commons Attribution 4.0 International.

10MB
Item Type:Article
Item Status:Live Archive

Abstract

It is of significant importance for any classification and recognition system, which claims near or better than human performance to be immune to small perturbations in the dataset. Researchers found out that neural networks are not very robust to small perturbations and can easily be fooled to persistently misclassify by adding a particular class of noise in the test data. This, so-called adversarial noise severely deteriorates the performance of neural networks, which otherwise perform really well on unperturbed dataset. It has been recently proposed that neural networks can be made robust against adversarial noise by training them using the data corrupted with adversarial noise itself. Following this approach, in this paper, we propose a new mechanism to generate a powerful adversarial noise model based on K-support norm to train neural networks. We tested our approach on two benchmark datasets, namely the MNIST and STL-10, using muti-layer perceptron and convolutional neural networks. Experimental results demonstrate that neural networks trained with the proposed technique show significant improvement in robustness as compared to state-of-the-art techniques.

Keywords:Computer Vision, Robustness, Training, Mathematical model, Biological neural networks, Optimization, Support vector machines
Subjects:G Mathematical and Computer Sciences > G740 Computer Vision
Divisions:College of Science > School of Computer Science
ID Code:52390
Deposited On:18 Nov 2022 10:50

Repository Staff Only: item control page