SOTAVerified

Adversarial Defense by Suppressing High-frequency Components

2019-08-19Code Available0· sign in to hype

Zhendong Zhang, Cheolkon Jung, Xiaolong Liang

Code Available — Be the first to reproduce this paper.

Reproduce

Code

Abstract

Recent works show that deep neural networks trained on image classification dataset bias towards textures. Those models are easily fooled by applying small high-frequency perturbations to clean images. In this paper, we learn robust image classification models by removing high-frequency components. Specifically, we develop a differentiable high-frequency suppression module based on discrete Fourier transform (DFT). Combining with adversarial training, we won the 5th place in the IJCAI-2019 Alibaba Adversarial AI Challenge. Our code is available online.

Tasks

Reproductions