NeurIPS 2018poster68 citations

Thwarting Adversarial Examples: An $L_0$-Robust Sparse Fourier Transform

Mitali Bafna, Jack Murtagh, Nikhil Vyas

Abstract

We give a new algorithm for approximating the Discrete Fourier transform of an approximately sparse signal that is robust to worst-case $L_0$ corruptions, namely that some coordinates of the signal can be corrupt arbitrarily. Our techniques generalize to a wide range of linear transformations that are used in data analysis such as the Discrete Cosine and Sine transforms, the Hadamard transform, and their high-dimensional analogs. We use our algorithm to successfully defend against worst-case $L_0$ adversaries in the setting of image classification. We give experimental results on the Jacobian-based Saliency Map Attack (JSMA) and the CW $L_0$ attack on the MNIST and Fashion-MNIST datasets as well as the Adversarial Patch on the ImageNet dataset.

BibTeX
@inproceedings{NEURIPS2018_aef546f2,
 author = {Bafna, Mitali and Murtagh, Jack and Vyas, Nikhil},
 booktitle = {Advances in Neural Information Processing Systems},
 editor = {S. Bengio and H. Wallach and H. Larochelle and K. Grauman and N. Cesa-Bianchi and R. Garnett},
 pages = {},
 publisher = {Curran Associates, Inc.},
 title = {Thwarting Adversarial Examples: An L\_0-Robust Sparse Fourier Transform},
 url = {https://proceedings.neurips.cc/paper_files/paper/2018/file/aef546f29283b6ccef3c61f58fb8e79b-Paper.pdf},
 volume = {31},
 year = {2018}
}
Thwarting Adversarial Examples: An $L_0$-Robust Sparse Fourier Transform · NeurIPS 2018