Related Experiment Video
Updated: Oct 14, 2025

06:09
P300-Based Brain-Computer Interface Speller Performance Estimation with Classifier-Based Latency Estimation
Published on: September 8, 2023
706
Privacy Preserving Defense For Black Box Classifiers Against On-Line Adversarial Attacks
IEEE Transactions on Pattern Analysis and Machine Intelligence
|November 8, 2021
Summary
This study introduces a new privacy-preserving method to defend deep learning models against adversarial attacks. The framework uses iterative image purifiers and Bayesian uncertainties to reliably detect and remove adversarial perturbations, ensuring image integrity.
Area of Science:
- Computer Science
- Artificial Intelligence
- Machine Learning
Background:
- Deep learning models are susceptible to adversarial attacks, where subtle image alterations cause misclassification.
- Current defense methods rely on classification accuracy, which is insufficient for validating adversarial-free images, especially in online applications without ground truth.
Purpose of the Study:
- To propose a novel privacy-preserving framework to defend black-box classifiers against adversarial attacks.
- To introduce an iterative defense mechanism using an ensemble of image purifiers validated by Bayesian uncertainties.
- To develop privacy-preserving Knowledge Distillation (KD) approaches for mimicking black-box classifier performance.
Main Methods:
- An ensemble of iterative adversarial image purifiers is employed.
- Bayesian uncertainties are used for continuous performance validation in a closed loop.
- Three novel privacy-preserving Knowledge Distillation (KD) methods leverage prior meta-information.
Main Results:
- The proposed framework effectively converts single-step defenses into iterative ones.
- Experimental results on six benchmark datasets demonstrate consistent detection and purification/rejection of adversarial examples.
- The existence of an optimal distribution for purified images, reaching a theoretical purification lower bound, is proven.
Conclusions:
- The developed framework offers a robust defense against adversarial attacks for black-box classifiers.
- The approach provides a reliable method for validating and purifying images in real-world applications.
- The study advances the field of adversarial robustness in deep learning with privacy-preserving techniques.
Related Concept Videos
Blinding
3.5K
Blinding is a commonly used method of not telling participants which treatment a subject is receiving. Blinding is a critical part of a randomized control trial or RCT. It reduces the bias that affects the results. In an RCT, blinding is used in the form of a placebo. A placebo effect occurs when untreated subjects falsely believe they have received the treatment and report improved symptoms. A placebo or a dummy treatment is administered to subjects to negate the bias caused by such an effect.
3.5K
Detection of Black Holes
2.3K
Although black holes were theoretically postulated in the 1920s, they remained outside the domain of observational astronomy until the 1970s.
Their closest cousins are neutron stars, which are composed almost entirely of neutrons packed against each other, making them extremely dense. A neutron star has the same mass as the Sun but its diameter is only a few kilometers. Therefore, the escape velocity from their surface is close to the speed of light.
Not until the 1960s, when the first neutron...
Their closest cousins are neutron stars, which are composed almost entirely of neutrons packed against each other, making them extremely dense. A neutron star has the same mass as the Sun but its diameter is only a few kilometers. Therefore, the escape velocity from their surface is close to the speed of light.
Not until the 1960s, when the first neutron...
2.3K
Censoring Survival Data
278
Survival analysis is a statistical method used to analyze time-to-event data, often employed in fields such as medicine, engineering, and social sciences. One of the key challenges in survival analysis is dealing with incomplete data, a phenomenon known as "censoring." Censoring occurs when the event of interest (such as death, relapse, or system failure) has not occurred for some individuals by the end of the study period or is otherwise unobservable, and it might have many different...
278
Masking and Demasking Agents
2.8K
EDTA titrations may necessitate masking and demasking agents to temporarily protect a particular metal ion in a mixture from the EDTA reaction. These agents facilitate the sequential analysis of the metal ions by forming stable complexes with some—but not all—metal ions during certain steps.
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
2.8K
Generalization, Discrimination, and Extinction
898
Generalization, discrimination, and extinction are key concepts in operant conditioning that influence how behaviors are learned and maintained.
Generalization occurs when a behavior reinforced in one context is performed in similar situations. For instance, a student who studies diligently for calculus and receives excellent grades might apply the same study habits to psychology and history, expecting similar results. Generalization shows how learning in one setting can influence behavior in...
Generalization occurs when a behavior reinforced in one context is performed in similar situations. For instance, a student who studies diligently for calculus and receives excellent grades might apply the same study habits to psychology and history, expecting similar results. Generalization shows how learning in one setting can influence behavior in...
898
Survival Tree
181
Survival trees are a non-parametric method used in survival analysis to model the relationship between a set of covariates and the time until an event of interest occurs, often referred to as the "time-to-event" or "survival time." This method is particularly useful when dealing with censored data, where the event has not occurred for some individuals by the end of the study period, or when the exact time of the event is unknown.
Building a Survival Tree
Constructing a...
Building a Survival Tree
Constructing a...
181