Published April 13, 2021 | Version 1
Conference paper Open

Local Competition and Stochasticity for Adversarial Robustness in Deep Learning

  • 1. Cyprus University of Technology
  • 2. University of California
  • 3. National and Kapodistrian University of Athens

Description

This entry accommodates the main paper "Local Competition and Stochasticity for Adversarial Robustness in Deep Learning", AISTATS 2021, its supplemental material, as well as the Tensorflow-based code implementation. Further requirements and instructions are provided in the respective README.md file.

Abstract:
This work addresses adversarial robustness in deep learning by considering deep networks with stochastic local winner-takes-all (LWTA) activations. This type of network units result in sparse representations from each model layer, as the units are organized in blocks where only one unit generates a non-zero output. The main operating principle of the introduced units lies on stochastic arguments, as the network performs posterior sampling over competing units to select the winner. We combine these LWTA arguments with tools from the field of Bayesian non-parametrics, specifically the stick-breaking construction of the Indian Buffet Process, to allow for inferring the sub-part of each layer that is essential for modeling the data at hand. Then, inference is performed by means of stochastic variational Bayes. We perform a thorough experimental evaluation of our model using benchmark datasets. As we show, our method achieves high robustness to adversarial perturbations, with state-of-the-art performance in powerful adversarial attack schemes.

Files

adversarial_ecoc_lwta-main.zip

Files (834.4 kB)

Name Size Download all
md5:ae5f31d19b4c9c46a74ba72b81a7be9c
33.3 kB Preview Download
md5:213b6f1810b5bb8adc65f865a081e049
627.1 kB Preview Download
md5:1034666c8a59b683c0090bb0ac49beea
174.0 kB Preview Download

Additional details

Funding

aiD – aRTIFICIAL iNTELLIGENCE for the Deaf 872139
European Commission