Countering Adversarial Images using Input Transformations

Chuan GuoMayank RanaMoustapha CisseLaurens van der Maaten

article2018ICLR1,657 citations

Demonstrates that applying non-differentiable input transformations like image quilting and total variance minimization can effectively defend convolutional networks against strong adversarial attacks on ImageNet without requiring complex model modifications.

Listen

As deep learning systems are increasingly deployed in security-critical environments such as autonomous driving and medical imaging, their susceptibility to adversarial attacks poses a serious operational risk. Adversaries can introduce small, imperceptible alterations to input images that cause state-of-the-art neural networks to make incorrect classifications. Existing defense strategies generally fall into two categories: model-specific approaches that modify neural networks but often break when attackers adapt their strategies, and model-agnostic input defenses that historically proved too simple to be fully effective.

The article evaluates whether preprocessing input images with specialized transformations can effectively remove adversarial perturbations before images reach the classifier. The objective is to establish practical, model-agnostic defenses that maintain high classification accuracy on normal images while neutralizing diverse attack strategies, even when attackers have full knowledge of the classifier's internal architecture and parameters.

To assess this, the authors tested five image transformation techniques: cropping and rescaling, bit-depth reduction, JPEG compression, total variation minimization (a method that reconstructs smooth images after randomly dropping pixels), and image quilting (which synthesizes images using small, clean reference patches). These defenses were evaluated on the standard ImageNet dataset using deep residual networks against four prominent attack methods across both black-box scenarios (where the adversary has no access to the model) and gray-box scenarios (where the adversary knows the network parameters but not the specific preprocessing defense).

The evaluation revealed several key findings. First, training the neural networks directly on transformed images substantially improved defense performance compared to merely applying transformations at test time. Second, image quilting and total variation minimization served as the most resilient defenses; under strong black-box attacks, image quilting neutralized 80% to 90% of threats. Third, combining multiple defenses—specifically ensembling cropping, total variation minimization, and quilting across modern architectures—achieved an accuracy of approximately 71%, suffering at most a 6% performance drop under heavy attack. Fourth, in gray-box evaluations against iterative attacks such as DeepFool, transformation-based defenses achieved over 50% accuracy, outperforming prior state-of-the-art ensemble adversarial training methods by 18 to 24 times.

These findings indicate that effective defenses must rely on transformations that are non-differentiable and inherently randomized. Randomness prevents adversaries from mathematically calculating exact perturbations, forcing them to solve a significantly harder problem of fooling a broad distribution of potential image reconstructions. This offers an accessible, scalable way to harden existing computer vision pipelines without requiring complex, attack-specific retraining protocols.

Organizations deploying vision systems should consider adopting randomized preprocessing pipelines—particularly combining spatial cropping, total variation minimization, and quilting—and retraining core classifiers on these transformed inputs. While effective against current attack vectors, these defenses assume the adversary does not know the specific real-time preprocessing configuration. Future engineering work should evaluate how these defenses withstand adaptive attacks designed specifically to bypass randomized transformations, and investigate extending similar transformation defenses to other domains such as speech and audio processing.

Cover for Countering Adversarial Images using Input Transformations

Abstract

This paper investigates strategies that defend against adversarial-example attacks on image-classification systems by transforming the inputs before feeding them to the system. Specifically, we study applying image transformations such as bit-depth reduction, JPEG compression, total variance minimization, and image quilting before feeding the image to a convolutional network classifier. Our experiments on ImageNet show that total variance minimization and image quilting are very effective defenses in practice, in particular, when the network is trained on transformed images. The strength of those defenses lies in their non-differentiable nature and their inherent randomness, which makes it difficult for an adversary to circumvent the defenses. Our best defense eliminates 60% of strong gray-box and 90% of strong black-box attacks by a variety of major attack methods

Table of Contents

  • 1 Introduction
  • 2 Problem Definition
  • 3 Adversarial Attacks
  • 4 Defenses
  • 4.1 Image cropping-rescaling, bit-depth reduction, and compression
  • 4.2 Total variance minimization
  • 4.3 Image quilting
  • 5 Experiments
  • 5.1 Experimental Setup
  • 5.2 Gray Box: Image Transformations at Test Time
  • 5.3 Black Box: Image Transformations at Training and Test Time
  • 5.4 Black Box: Ensembling and Model Transfer
  • 5.5 Gray Box: Image Transformations at Training and Test Time
  • 5.6 Comparison with Prior Work
  • 6 Discussion
  • References

Knowls

  1. Knowl 1 — Total Variation Minimization with Pixel Dropout Defense

    model/method

    Total variation (TV) minimization combined with random pixel dropout removes adversarial perturbations from an image by reconstructing the simplest smooth image consistent with a randomly sampled subset of pixels.

    Let x∈[0,1]H×W×Cx \in [0, 1]^{H \times W \times C} be an input image (height HH, width WW, channels CC). A binary Bernoulli mask X∈{0,1}H×W×CX \in \{0, 1\}^{H \times W \times C} is sampled independently for each pixel location (i,j,k)(i, j, k) with dropout probability pdrop=0.5p_{\text{drop}} = 0.5, where X(i,j,k)=1X(i, j, k) = 1 denotes a dropped pixel and (1−X)(1 - X) selects the retained pixels. The denoised reconstruction z∈[0,1]H×W×Cz \in [0, 1]^{H \times W \times C} is found by solving the convex optimization problem:

    min⁡z∥(1−X)⊙(z−x)∥2+λTV⋅TVp(z)\min_{z} \|(1 - X) \odot (z - x)\|_2 + \lambda_{\text{TV}} \cdot \text{TV}_p(z)

    where ⊙\odot represents element-wise multiplication, λTV=0.03\lambda_{\text{TV}} = 0.03 is the regularization parameter, and TVp(z)\text{TV}_p(z) denotes the anisotropic LpL_p-total variation:

    TVp(z)=∑k=1C[∑i=2H∥z(i,:,k)−z(i−1,:,k)∥p+∑j=2W∥z(:,j,k)−z(:,j−1,k)∥p]\text{TV}_p(z) = \sum_{k=1}^C \left[ \sum_{i=2}^H \|z(i, :, k) - z(i - 1, :, k)\|_p + \sum_{j=2}^W \|z(:, j, k) - z(:, j - 1, k)\|_p \right]

    With p=2p = 2, this objective is convex and solved using the split Bregman method. Because fine-scale adversarial perturbations are localized and low in total energy, reconstructing from the subsampled pixels via total variation smoothness suppresses the adversarial signal while preserving coarse semantic image structure.

  2. Knowl 2 — Clean Patch-Based Image Quilting Defense

    model/method

    Image quilting defense removes adversarial perturbations by synthesizing a clean replacement image using patch substitution from a database of unperturbed image patches.

    The defense maintains a database D\mathcal{D} of 1,000,0001,000,000 clean patches of size 5×55 \times 5 pixels sampled randomly from clean training images. For a given input image xx:

    1. For each predefined grid location, the corresponding 5×55 \times 5 patch in xx is extracted.
    2. The KK nearest neighbor patches to this query patch (measured by Euclidean distance in pixel space) are retrieved from the database D\mathcal{D}.
    3. One of the KK nearest clean patches is chosen uniformly at random (e.g., K=1K = 1 for deterministic nearest neighbor, or K=10K = 10 for randomized neighbor selection).
    4. Minimum graph cuts are computed across overlapping boundary regions between adjacent placed patches to eliminate seam artifacts.

    Because the patch database contains only clean image fragments, the synthesized image consists entirely of natural image textures, eliminating localized adversarial artifacts that do not exist in clean natural patches.

  3. Knowl 3 — Retraining Classifiers on Transformed Inputs

    empirical result

    Applying image transformations solely at test time to standard convolutional networks trained on clean images yields suboptimal classification accuracy (achieving only 30–40% top-1 accuracy under attack on ImageNet) because the model is not invariant to the distortion introduced by the transformation itself.

    When classifiers (e.g., ResNet-50) are retrained on images transformed during training with the same transformation applied at test time (e.g., image quilting, total variation minimization, JPEG compression, or bit-depth reduction):

    • The network acquires invariance to the transformation artifacts, recovering high classification accuracy.
    • Against strong black-box attacks (FGSM, I-FGSM, DeepFool, and Carlini-Wagner L2L_2) with perturbation magnitudes up to a normalized L2L_2-dissimilarity of 0.08, retraining with image quilting eliminates 80–90% of attacks.
    • Under gray-box attacks (where the adversary targets the transformation-trained network weights but lacks access to the test-time transformation pipeline), networks protected by total variation minimization, image quilting, or random cropping maintain up to 50% top-1 accuracy.
  4. Knowl 4 — Ensembling and Model Transfer Defense Pipeline

    model/method

    An ensemble defense combines multiple randomized input transformations and architectural transfer to defend against black-box adversarial attacks:

    1. Quilting and Stochastic TV Minimization Ensembling: The ensemble prediction combines the predicted class probability distribution from the image quilting defense (weighted by 0.50.5) with predictions from 1010 independent stochastic TV minimization reconstructions (weighted by 0.050.05 each). In each TV minimization run, pixel dropout mask XX is sampled independently.
    2. Multi-Crop Integration: Prior to classification, 10 random sub-crops of size 90×9090 \times 90 pixels are extracted from the 224×224224 \times 224 transformed images, rescaled back to 224×224224 \times 224, and their predictions are averaged.
    3. Cross-Architecture Model Transfer: Transformed inputs generated against a source architecture (such as ResNet-50) are fed to structurally distinct classifiers, such as ResNet-101, DenseNet-169, or Inception-v4.

    Ensembling different transformations improves top-1 classification accuracy by 1–2%1\text{--}2\%, and transferring to alternate architectures improves accuracy by an additional 2–3%2\text{--}3\%.

  5. Knowl 5 — Performance Comparison with Ensemble Adversarial Training

    data/table
    Attack Cropping TVM Quilting Ensemble Training
    No Attack 65.41 66.29 69.66 80.30
    FGSM 49.52 31.37 39.55 69.15
    I-FGSM 43.89 40.99 33.22 5.07
    DeepFool 44.92 44.69 34.54 1.84
    CW-L2 41.06 48.41 30.51 22.23

    The table displays top-1 classification accuracy (%) on ImageNet against gray-box adversarial attacks generated against ResNet-50 models trained on input-transformed images compared to an Inception-ResNet-v2 model trained using ensemble adversarial training (Tramèr et al., 2017). Adversarial examples were generated at an average normalized L2L_2-dissimilarity of 0.06.

    While ensemble adversarial training achieves higher accuracy against single-step FGSM (69.15% vs 49.52% for cropping) because FGSM was included in its training objective, it collapses on iterative attacks (5.07% on I-FGSM, 1.84% on DeepFool, and 22.23% on CW-L2). In contrast, transformation-based defenses maintain consistent robustness (30–48% accuracy) across all iterative attacks, providing 18× to 24× higher accuracy against DeepFool attacks.

  6. Knowl 6 — Classification Accuracies of Ensemble Defenses Across Architectures

    data/table
    Quilting TVM + Quilting Cropping + TVM + Quilting
    Attack RN50 RN101 DN169 Iv4 RN50 RN101 DN169 Iv4 RN50 RN101 DN169 Iv4
    No Attack 70.07 72.56 70.18 73.01 72.38 74.74 73.10 75.55 72.14 74.53 72.92 75.10
    FGSM 65.45 68.50 65.96 67.53 65.70 68.77 67.09 69.19 66.65 69.75 67.86 70.37
    I-FGSM 65.59 68.72 66.16 69.29 65.84 69.10 67.32 71.05 67.03 70.14 68.20 71.52
    DeepFool 65.20 68.73 65.86 68.70 65.80 69.34 67.40 71.03 67.11 70.49 68.62 71.47
    CW-L2 64.11 67.72 65.00 68.14 63.99 68.20 66.08 70.13 65.31 69.14 66.96 70.50

    The table reports top-1 classification accuracy (%) on ImageNet across four network architectures—ResNet-50 (RN50), ResNet-101 (RN101), DenseNet-169 (DN169), and Inception-v4 (Iv4)—under three defense configurations against four black-box attacks generated against ResNet-50 at average normalized L2L_2-dissimilarity of 0.06.

    The combined defense pipeline (Cropping + TVM + Quilting) paired with Inception-v4 achieves over 70% top-1 accuracy across all attack types (FGSM: 70.37%, I-FGSM: 71.52%, DeepFool: 71.47%, CW-L2: 70.50%), degrading by at most 4.6% relative to the clean baseline (75.10%).

  7. Knowl 7 — Normalized L2-Dissimilarity and Adversarial Threat Models

    definition

    Let X=[0,1]H×W×C\mathcal{X} = [0, 1]^{H \times W \times C} be the image space and h:X→{1,…,K}h: \mathcal{X} \to \{1, \dots, K\} be an image classifier. For a clean image x∈Xx \in \mathcal{X}, a non-targeted adversarial example x′∈Xx' \in \mathcal{X} satisfies h(x′)≠h(x)h(x') \neq h(x) subject to a dissimilarity constraint d(x,x′)≤ρd(x, x') \le \rho.

    Given a set of NN images {x1,…,xN}\{x_1, \dots, x_N\} and their perturbations {x1′,…,xN′}\{x'_1, \dots, x'_N\}, the adversary perturbation magnitude is evaluated using the normalized L2L_2-dissimilarity:

    1N∑n=1N∥xn−xn′∥2∥xn∥2\frac{1}{N} \sum_{n=1}^N \frac{\|x_n - x'_n\|_2}{\|x_n\|_2}

    Two threat models govern defense evaluation:

    • Black-box attack: The adversary does not have direct access to the target model or defense mechanism and generates attacks using a separately trained proxy model.
    • Gray-box attack: The adversary has full access to the classifier architecture and model parameters, but does not have access to or knowledge of the defense transformation g(⋅)g(\cdot) applied to inputs at inference time.
  8. Knowl 8 — Lightweight Input Transformations: Cropping, Bit-Depth Reduction, and JPEG Compression

    model/method

    Three lightweight image transformation defenses reduce adversarial perturbation strength:

    1. Image Cropping-Rescaling: At inference time, 30 random image crops of size 90×9090 \times 90 are sampled from the 224×224224 \times 224 input image, rescaled bilinearly back to 224×224224 \times 224, and evaluated by the classifier. The final class prediction is obtained by averaging predictions over all 30 crops. This spatial modification disrupts the spatial alignment and scale of adversarial perturbations.
    2. Bit-Depth Reduction: The color resolution of each pixel channel is quantized from 8 bits (256256 levels) down to 3 bits (88 levels), removing low-amplitude adversarial perturbations in pixel values.
    3. JPEG Compression: The image is compressed and decompressed using the standard JPEG algorithm at quality factor 75 (out of 100), eliminating high-frequency spatial perturbations via Discrete Cosine Transform quantization.
  9. Knowl 9 — Non-Differentiability and Stochasticity as Robustness Mechanisms

    theoretical result

    The resistance of model-agnostic input-transformation defenses g:X→Xg: \mathcal{X} \to \mathcal{X} against gradient-based adversarial attacks depends on two core properties:

    1. Non-Differentiability: Differentiable transformations (such as linear filtering or median filtering) permit backpropagation of loss gradients through the defense to construct adaptive adversarial inputs. In contrast, total variation minimization requires solving an internal optimization problem, and image quilting involves discrete patch lookup and graph-cut optimization, both preventing direct backward gradient propagation.
    2. Stochasticity: Deterministic transformations can be circumvented once identified. Introducing randomness (such as Bernoulli pixel dropout in TV minimization, random choice among KK nearest clean patches in quilting, or random sub-crop sampling) forces the adversary to optimize perturbations against an expectation over a distribution of transformed inputs Eg∼G[h(g(x′))]\mathbb{E}_{g \sim \mathcal{G}}[h(g(x'))], which is substantially harder than finding an adversarial perturbation for a fixed deterministic input.

Coverage note — No substantial contributed material was omitted; the extraction covers all five transformation methods, threat models, training/testing regimes, ensembling pipelines, theoretical defense mechanisms, and experimental comparison tables.

References

  1. 1.Dario Amodei, Rishita Anubhai, Eric Battenberg, Carl Case, Jared Casper, Bryan Catanzaro, Jingdong Chen, Mike Chrzanowski, Adam Coates, Greg Diamos, et al. Deep Speech 2: End-to-end speech recognition in English and Mandarin. CoRR, abs/1512.02595, 2015.
  2. 2.Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Srndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli. Evasion attacks against machine learning at test time. In Proc. ECML, pp. 387–402, 2013.
  3. 3.Mariusz Bojarski, Davide Del Testa, Daniel Dworakowski, Bernhard Firner, Beat Flepp, Prasoon Goyal, Lawrence D Jackel, Mathew Monfort, Urs Muller, Jiakai Zhang, et al. End-to-end learning for self-driving cars. CoRR, abs/1604.07316, 2016.
  4. 4.Yuri Boykov, Olga Veksler, and Ramin Zabih. Fast approximate energy minimization via graph cuts. IEEE Transactions on Pattern Analysis and Machine Intelligence, 23(11):1222–1239, 2001.
  5. 5.Antoni Buades. A non-local algorithm for image denoising. In Proc. CVPR, pp. 60–65, 2005.
  6. 6.Nicholas Carlini and David A. Wagner. Towards evaluating the robustness of neural networks. In IEEE Symposium on Security and Privacy, pp. 39–57, 2017.
  7. 7.Moustapha Cisse, Yossi Adi, Natalia Neverova, and Joseph Keshet. Houdini: Fooling deep structured prediction models. CoRR, abs/1707.05373, 2017a.
  8. 8.Moustapha Cisse, Piotr Bojanowski, Edouard Grave, Yann Dauphin, and Nicolas Usunier. Parseval networks: Improving robustness to adversarial examples. CoRR, abs/1704.08847, 2017b.
  9. 9.Weisheng Dong, Lei Zhang, and Guangming Shi. Centralized sparse representation for image restoration. In Proc. ICCV, pp. 1259–1266, 2011.
  10. 10.Gintare Karolina Dziugaite, Zoubin Ghahramani, and Daniel Roy. A study of the effect of JPG compression on adversarial images. CoRR, abs/1608.00853, 2016.
  11. 11.Alexei Efros and William Freeman. Image quilting for texture synthesis and transfer. In Proc. SIGGRAPH, pp. 341–346, 2001.
  12. 12.Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. Analysis of classifiers’ robustness to adversarial perturbations. CoRR, abs/1502.02590, 2015.
  13. 13.Alhussein Fawzi, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard. Robustness of classifiers: From adversarial to random noise. In Proc. NIPS, pp. 1632–1640, 2016.
  14. 14.Tom Goldstein and Stanley Osher. The split Bregman method for L1-regularized problems. SIAM Journal of Imaging Science, 2(2):323–343, April 2009.
  15. 15.Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial examples. In Proc. ICLR, 2015.
  16. 16.Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. Deep residual learning for image recognition. In Proc. CVPR, pp. 770–778, 2016.
  17. 17.Gao Huang, Zhuang Liu, Kilian Weinberger, and Laurens van der Maaten. Densely connected convolutional networks. In Proc. CVPR, pp. 2261–2269, 2017.
  18. 18.Auguste Kerckhoffs. La cryptographie militaire. Journal des sciences militaires, IX:5–83, 161–191, 1883.
  19. 19.Diederik Kingma and Jimmy Ba. Adam: A method for stochastic optimization. CoRR, abs/1412.6980, 2014.
  20. 20.Alexey Kurakin, Ian Goodfellow, and Samy Bengio. Adversarial machine learning at scale. CoRR, abs/1611.01236, 2016a.
  21. 21.Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio. Adversarial examples in the physical world. CoRR, abs/1607.02533, 2016b.
  22. 22.Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. Delving into transferable adversarial examples and black-box attacks. CoRR, abs/1611.02770, 2016.
  23. 23.Jiajun Lu, Hussein Sibai, Evan Fabry, and David Forsyth. No need to worry about adversarial examples in object detection in autonomous vehicles. CoRR, abs/1707.03501, 2017.
  24. 24.Chris Maddison, Andriy Mnih, and Yee-Whye Teh. The concrete distribution: A continuous relaxation of discrete random variables. In Proc. ICLR, 2017.
  25. 25.Marco Melis, Ambra Demontis, Battista Biggio, Gavin Brown, Giorgio Fumera, and Fabio Roli. Is deep learning safe for robot vision? adversarial examples against the icub humanoid. CoRR, abs/1708.06939, 2017.
  26. 26.Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard. Deepfool: A simple and accurate method to fool deep neural networks. In Proc. CVPR, pp. 2574–2582, 2016.
  27. 27.Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. Universal adversarial perturbations. In Proc. CVPR, pp. 86–94, 2017.
  28. 28.Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. Distillation as a defense to adversarial perturbations against deep neural networks. In IEEE Symposium on Security and Privacy, pp. 582–597, 2016.
  29. 29.Leonid Rudin, Stanley Osher, and Emad Fatemi. Nonlinear total variation based noise removal algorithms. Physica D, 60:259–268, 1992.
  30. 30.Uri Shaham, Yutaro Yamada, and Sahand Negahban. Understanding adversarial training: Increasing local stability of neural nets through robust optimization. CoRR, abs/1511.05432, 2015.
  31. 31.Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. Intriguing properties of neural networks. In In Proc. ICLR, 2014.
  32. 32.Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna. Rethinking the inception architecture for computer vision. In Proc. CVPR, pp. 2818–2826, 2016.
  33. 33.Christian Szegedy, Sergey Ioffe, Vincent Vanhoucke, and Alexander Alemi. Inception-v4, Inception-ResNet and the impact of residual connections on learning. In Proc. AAAI, pp. 4278–4284, 2017.
  34. 34.Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Dan Boneh, and Patrick D. McDaniel. Ensemble adversarial training: Attacks and defenses. CoRR, abs/1705.07204, 2017.
  35. 35.Qinglong Wang, Wenbo Guo, Kaixuan Zhang, Alexander G. Ororbia II, Xinyu Xing, C. Lee Giles, and Xue Liu. Adversary resistant deep neural networks with an application to malware detection. CoRR, abs/1610.01239, 2016a.
  36. 36.Qinglong Wang, Wenbo Guo, Kaixuan Zhang, Alexander G. Ororbia II, Xinyu Xing, C. Lee Giles, and Xue Liu. Learning adversary-resistant deep neural networks. CoRR, abs/1612.01401, 2016b.
  37. 37.Weilin Xu, David Evans, and Yanjun Qi. Feature squeezing: Detecting adversarial examples in deep neural networks. CoRR, abs/1704.01155, 2017.
  38. 38.Guoming Zhang, Chen Yan, Xiaoyu Ji, Taimin Zhang, Tianchen Zhang, and Wenyuan Xu. Dolphinatack: Inaudible voice commands. CoRR, abs/1708.09537, 2017.

Citation

MLA
Guo, C., et al. “Countering Adversarial Images Using Input Transformations”. arXiv, 2017, http://arxiv.org/abs/1711.00117v3.
APA
Guo, C., Rana, M., Cisse, M., & Maaten, L. van . der . (2017). Countering Adversarial Images using Input Transformations. arXiv. http://arxiv.org/abs/1711.00117v3
Chicago
Guo, C., M. Rana, M. Cisse, and L. van . der . Maaten. 2017. “Countering Adversarial Images Using Input Transformations”. arXiv. http://arxiv.org/abs/1711.00117v3.
Harvard
Guo, C. et al. (2017) “Countering Adversarial Images using Input Transformations”, arXiv [Preprint]. Available at: http://arxiv.org/abs/1711.00117v3.
Vancouver
1. Guo C, Rana M, Cisse M, Maaten L van der (2017) Countering Adversarial Images using Input Transformations. arXiv

BibTeX

@article{guo2017countering,
  title = {Countering Adversarial Images using Input Transformations},
  author = {Guo, Chuan and Rana, Mayank and Cisse, Moustapha and Maaten, Laurens van der},
  year = {2017},
  journal = {arXiv},
  url = {http://arxiv.org/abs/1711.00117v3},
  eprint = {1711.00117}
}
Metadata:arXiv

Source Code

This paper has an official code repository available. Click below to access the source code.

View Repository

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: Authors