2023
Defending from Physically-Realizable Adversarial Attacks through Internal Over-Activation Analysis
AAAI 2023technical
This work presents Z-Mask, an effective and deterministic strategy to improve the adversarial robustness of convolutional networks against physically-realizable adversarial attacks. The presented defense relies on specific Z-score analysis performed on the internal network features to detect and mas…