On the Robustness of the CVPR 2018 White-Box Adversarial Example Defenses
2018-04-10Code Available0· sign in to hype
Anish Athalye, Nicholas Carlini
Code Available — Be the first to reproduce this paper.
ReproduceCode
- github.com/anishathalye/Guided-DenoiseOfficialIn papertf★ 0
- github.com/anishathalye/pixel-deflectiontf★ 0
Abstract
Neural networks are known to be vulnerable to adversarial examples. In this note, we evaluate the two white-box defenses that appeared at CVPR 2018 and find they are ineffective: when applying existing techniques, we can reduce the accuracy of the defended models to 0%.