Related Experiment Video
Updated: Nov 2, 2025

Author Spotlight: Using Hyperpolarized Xenon-129 MRI to Study Lung Diseases
Published on: January 5, 2024
Removing Adversarial Noise via Low-Rank Completion of High-Sensitivity Points
Abstract:
Deep neural networks are fragile under adversarial attacks. In this work, we propose to develop a new defense method based on image restoration to remove adversarial attack noise. Using the gradient information back-propagated over the network to the input image, we identify high-sensitivity keypoints which have significant contributions to the image classification performance. We then partition the image pixels into the two groups: high-sensitivity and low-sensitivity points. For low-sensitivity pixels, we use a total variation (TV) norm-based image smoothing method to remove adversarial attack noise. For those high-sensitivity keypoints, we develop a structure-preserving low-rank image completion method. Based on matrix analysis and optimization, we derive an iterative solution for this optimization problem. Our extensive experimental results on the CIFAR-10, SVHN, and Tiny-ImageNet datasets have demonstrated that our method significantly outperforms other defense methods which are based on image de-noising or restoration, especially under powerful adversarial attacks.
Related Concept Videos
Aliasing
If the sampling frequency is below the Nyquist rate, these replicas overlap, preventing the original...
Reducing Line Loss
With a step-up transformer at the source, the voltage is increased, thereby reducing the current in the transmission lines since power loss...
Upsampling
Quantifying and Rejecting Outliers: The Grubbs Test
Difference from Background: Limit of Detection
The LOD indicates the presence or absence...
NMR Spectrometers: Resolution and Error Correction
