Jujutsu: A Two-stage Defense against Adversarial Patch Attacks on Deep Neural Networks
作者
Z. Chen,Pritam Dash,Karthik Pattabiraman
标识
DOI:10.1145/3579856.3582816
摘要
Adversarial patch attacks create adversarial examples by injecting arbitrary distortions within a bounded region of the input to fool deep neural networks (DNNs). These attacks are robust (i.e., physically-realizable) and universally malicious, and hence represent a severe security threat to real-world DNN-based systems.