3 ms·
Can we use one pixel attack to train network? We would generate adversarial examples to train network. Having ability to create Training Set that maximizes lea
by SurgeonOfDeath 9y ago
Can we use one pixel attack to train network? We would generate adversarial examples to train network.
Having ability to create Training Set that maximizes learning factor for NN sounds amazing but I think we would run to other adversarial examples.
- haraldurt 9y agoAugmenting your training dataset with adversarial examples is known as adversarial training, see e.g. [0] for a recent overview with empirical results. This seems to be a good first step in defending against such attacks, though the most naive approach of adversarial training doesn't work as well as you'd expect. [0] https://openreview.net/forum?id=rkZvSe-RZ https://openreview.net/forum?id=rkZvSe-RZ
- hajile 9y agoThere are a nearly infinite amount of forgery possibilities. The best solution seems to be making multiple networks with different approaches and training sets. Use a consensus or refer to a human if there is none. Finding holes should become harder with this approach.