← Search

Giulio Rossolini

2 accepted papers

2023

Defending from Physically-Realizable Adversarial Attacks through Internal Over-Activation Analysis

AAAI 2023technical

This work presents Z-Mask, an effective and deterministic strategy to improve the adversarial robustness of convolutional networks against physically-realizable adversarial attacks. The presented defense relies on specific Z-score analysis performed on the internal network features to detect and mas…

Cited by 14SourcePDFScholar
2023

Robust-by-Design Classification via Unitary-Gradient Neural Networks

AAAI 2023technical

The use of neural networks in safety-critical systems requires safe and robust models, due to the existence of adversarial attacks. Knowing the minimal adversarial perturbation of any input x, or, equivalently, knowing the distance of x from the classification boundary, allows evaluating the classif…

Cited by 7SourcePDFScholar