Sensitivity Based Robust Learning With Sampling In Adversarial Environment

Abstract

Although Deep Neural Networks achieve excellent results in many applications, their security issue is one of the concerns. Many studies suggest that Deep Neural Networks can be easily misled by adversarial attack. Sensitivity training method enhances the robustness of Deep Neural networks. However, injecting sensitivity samples for all training samples increases the training time significantly. This study investigates whether generating sensitivity samples for all training samples is necessary. A model trained by using sensitivity samples for selected training samples is proposed. The method is evaluated and compared with the traditional one and the adversarial learning method experimentally. The results suggest that the robustness of the models using sensitivity samples for the partial and full training sets is similar. The time complexity of sensitivity training methods can be reduced.

Publication
Neurocomputing, 116-121

Lab Members

Patrick Chan
Patrick Chan
Associate Professor, Vice Dean

Patrick Chan works on machine learning, deep learning, image processing, adversarial learning, and secure machine learning.