Skip to main content

Showing 1–1 of 1 results for author: Granda, R

Searching in archive cs. Search in all archives.
.
  1. arXiv:2010.15974  [pdf, other

    cs.CV cs.CR cs.LG

    Can the state of relevant neurons in a deep neural networks serve as indicators for detecting adversarial attacks?

    Authors: Roger Granda, Tinne Tuytelaars, Jose Oramas

    Abstract: We present a method for adversarial attack detection based on the inspection of a sparse set of neurons. We follow the hypothesis that adversarial attacks introduce imperceptible perturbations in the input and that these perturbations change the state of neurons relevant for the concepts modelled by the attacked model. Therefore, monitoring the status of these neurons would enable the detection of… ▽ More

    Submitted 29 October, 2020; originally announced October 2020.