Publications
Sort:
Open Access Research Article Issue
EITGAN: A Transformation-based Network for recovering adversarial examples
Electronic Research Archive 2023, 31(11): 6634-6656
Published: 15 November 2023
Abstract PDF (8.1 MB) Collect
Downloads:0

Adversarial examples have been shown to easily mislead neural networks, and many strategies have been proposed to defend them. To address the problem that most transformation-based defense strategies will degrade the accuracy of clean images, we proposed an Enhanced Image Transformation Generative Adversarial Network (EITGAN). Positive perturbations were employed in the EITGAN to counteract adversarial effects while enhancing the classified performance of the samples. We also used the image super-resolution method to mitigate the effect of adversarial perturbations. The proposed method does not require modification or retraining of the classifier. Extensive experiments demonstrated that the enhanced samples generated by the EITGAN effectively defended against adversarial attacks without compromising human visual recognition, and their classification performance was superior to that of clean images.

Total 1