Device and method to improve the robustness against ‘adversarial examples’
Abstract:
A computer-implemented method for assessing a robustness of a smoothed classifier for classifying sensor signals received from a sensor. The method includes: providing an input signal depending on the sensor signal, determining, by the smoothed classifier, a first value which characterizes a probability that the input signal, when subjected to noise will be classified as belonging to a first class, wherein the first class is a most probable class, determining, by the smoothed classifier, a second value which characterizes a probability that the input signal, when subjected to the noise, will be classified as belonging to a second class, wherein the second class is a second-most probable class, determining a robustness value on a first inverse value of a standard Gaussian cumulative distribution function at the first value and/or depending on a second inverse value of the standard Gaussian cumulative distribution function at the second value.
Information query
Patent Agency Ranking
0/0