Invention Grant
- Patent Title: Systems and methods for joint adversarial training by incorporating both spatial and pixel attacks
-
Application No.: US16399078Application Date: 2019-04-30
-
Publication No.: US10936910B2Publication Date: 2021-03-02
- Inventor: Haichao Zhang , Jianyu Wang
- Applicant: Baidu USA, LLC
- Applicant Address: US CA Sunnyvale
- Assignee: Baidu USA, LLC
- Current Assignee: Baidu USA, LLC
- Current Assignee Address: US CA Sunnyvale
- Agency: North Weber & Baugh LLP
- Main IPC: G06K9/62
- IPC: G06K9/62 ; G06N20/00

Abstract:
Described herein are embodiments for joint adversarial training methods that incorporate both spatial transformation-based and pixel-value based attacks for improving image model robustness. Embodiments of a spatial transformation-based attack with an explicit notion of budgets are disclosed and embodiments of a practical methodology for efficient spatial attack generation are also disclosed. Furthermore, both pixel and spatial attacks are integrated into embodiments of a generation model and the complementary strengths of each other are leveraged for improving the overall model robustness. Extensive experimental results on several benchmark datasets compared with state-of-the-art methods verified the effectiveness of the presented method.
Public/Granted literature
- US20200265271A1 SYSTEMS AND METHODS FOR JOINT ADVERSARIAL TRAINING BY INCORPORATING BOTH SPATIAL AND PIXEL ATTACKS Public/Granted day:2020-08-20
Information query