PCA as a defense against some adversaries
Name
CBMM-Memo-135.pdf
Size
2.58 MB
Format
Adobe PDF
Checksum (MD5)
90dfef07a7b81c59eeae902f1dd262c8
Author(s) • •
Aparne, Gupta
Banburski, Andrzej
Poggio, Tomaso
Date Issued
March 30, 2022
Publisher
Center for Brains, Minds and Machines (CBMM)
Series/Report no.
CBMM Memo;135
Abstract
Neural network classifiers are known to be highly vulnerable to adversarial perturbations in their inputs. Under the hypothesis that adversarial examples lie outside of the sub-manifold of natural images, previous work has investigated the impact of principal components in data on adversarial robustness. In this paper we show that there exists a very simple defense mechanism in the case where adversarial images are separable in a previously defined $(k,p)$ metric. This defense is very successful against the popular Carlini-Wagner attack, but less so against some other common attacks like FGSM. It is interesting to note that the defense is still successful for relatively large perturbations.
Persistent DSpace Link