Abstract: We present Vax-a-Net; a technique for immunizing convolutional neural networks (CNNs) against adversarial patch attacks (APAs). APAs insert visually overt, local regions (patches) into an image to induce misclassification. We introduce a conditional Generative Adversarial Network (GAN) architecture that simultaneously learns to synthesise patches for use in APAs, whilst exploiting those attacks to adapt a pre-trained target CNN to reduce its susceptibility to them. This approach enables resilience against APAs to be conferred to pre-trained models, which would be impractical with conventional adversarial training due to the slow convergence of APA methods. We demonstrate transferability of this protection to defend against existing APAs, and show its efficacy across several contemporary CNN architectures.

SlidesLive

Similar Papers

Multi-scale Attentive Residual Dense Network for Single Image Rain Removal
Xiang Chen (Shenyang Aerospace University ), Yufeng Huang (Shenyang Aerospace University)*, Lei Xu (Shenyang Fire Science and Technology Research Institute of MEM)
MCGKT-Net: Multi-level Context Gating Knowledge Transfer Network for Single Image Deraining
Kohei Yamamichi (Yamaguchi University)*, Xian-Hua Han (Yamaguchi University)
Trainable Structure Tensors for Autonomous Baggage Threat Detection Under Extreme Occlusion
Taimur Hassan (Khalifa University of Science and Technology)*, Naoufel Werghi (Khalifa University of Science and Technology)