3 ms·
Did you read the article? > We find that both adversarial training and defensive distillation accidentally perform a kind of gradient masking. Neither algorith
by lerid 10y ago
Did you read the article?
> We find that both adversarial training and defensive distillation accidentally perform a kind of gradient masking. Neither algorithm was explicitly designed to perform gradient masking, but gradient masking is apparently a defense that machine learning algorithms can invent relatively easily when they are trained to defend themselves and not given specific instructions about how to do so. If we transfer adversarial examples from one model to a second model that was trained with either adversarial training or defensive distillation, the attack often succeeds, even when a direct attack on the second model would fail. This suggests that both training techniques do more to flatten out the model and remove the gradient than to make sure it classifies more points correctly.
- deepnotderp 10y agoAh, haven't kept up with Adversarial examples research lately,sorry.