Skip to main navigation Skip to search Skip to main content

Robust Ensemble Model Training via Random Layer Sampling Against Adversarial Attack

Research output: Contribution to conferencePaperpeer-review

5 Citations (Scopus)

Abstract

Deep neural networks have achieved substantial achievements in several computer vision areas, but have vulnerabilities that are often fooled by adversarial examples that are not recognized by humans. This is an important issue for security or medical applications. In this paper, we propose an ensemble model training framework with random layer sampling to improve the robustness of deep neural networks. In the proposed training framework, we generate various sampled model through the random layer sampling and update the weight of the sampled model. After the ensemble models are trained, it can hide the gradient efficiently and avoid the gradient-based attack by the random layer sampling method. To evaluate our proposed method, comprehensive and comparative experiments have been conducted on three datasets. Experimental results show that the proposed method improves the adversarial robustness.

Original languageEnglish
Publication statusPublished - 2020
Event31st British Machine Vision Conference, BMVC 2020 - Virtual, Online
Duration: 7 Sept 202010 Sept 2020

Conference

Conference31st British Machine Vision Conference, BMVC 2020
CityVirtual, Online
Period7/09/2010/09/20

Bibliographical note

Publisher Copyright:
© 2020. The copyright of this document resides with its authors. It may be distributed unchanged freely in print or electronic forms.

Fingerprint

Dive into the research topics of 'Robust Ensemble Model Training via Random Layer Sampling Against Adversarial Attack'. Together they form a unique fingerprint.

Cite this