Skip to main navigation Skip to search Skip to main content

Can Attention Masks Improve Adversarial Robustness?

  • Pratik Vaishnavi
  • , Tianji Cong
  • , Kevin Eykholt
  • , Atul Prakash
  • , Amir Rahmati
  • Stony Brook University
  • University of Michigan, Ann Arbor

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

Deep Neural Networks (DNNs) are known to be susceptible to adversarial examples. Adversarial examples are maliciously crafted inputs that are designed to fool a model, but appear normal to human beings. Recent work has shown that pixel discretization can be used to make classifiers for MNIST highly robust to adversarial examples. However, pixel discretization fails to provide significant protection on more complex datasets. In this paper, we take the first step towards reconciling these contrary findings. Focusing on the observation that discrete pixelization in MNIST makes the background completely black and foreground completely white, we hypothesize that the important property for increasing robustness is the elimination of image background using attention masks before classifying an object. To examine this hypothesis, we create foreground attention masks for two different datasets, GTSRB and MS-COCO. Our initial results suggest that using attention mask leads to improved robustness. On the adversarially trained classifiers, we see an adversarial robustness increase of over 20% on MS-COCO.

Original languageEnglish
Title of host publicationEngineering Dependable and Secure Machine Learning Systems - Third International Workshop, EDSMLS 2020, Revised Selected Papers
EditorsOnn Shehory, Eitan Farchi, Guy Barash
PublisherSpringer Science and Business Media Deutschland GmbH
Pages14-22
Number of pages9
ISBN (Print)9783030621438
DOIs
StatePublished - 2020
Event3rd International Workshop on Engineering Dependable and Secure Machine Learning Systems, EDSMLS 2020 - New York City, United States
Duration: Feb 7 2020Feb 7 2020

Publication series

NameCommunications in Computer and Information Science
Volume1272
ISSN (Print)1865-0929
ISSN (Electronic)1865-0937

Conference

Conference3rd International Workshop on Engineering Dependable and Secure Machine Learning Systems, EDSMLS 2020
Country/TerritoryUnited States
CityNew York City
Period02/7/2002/7/20

Keywords

  • Computer vision
  • Machine learning
  • Security

Fingerprint

Dive into the research topics of 'Can Attention Masks Improve Adversarial Robustness?'. Together they form a unique fingerprint.

Cite this