| Zugriffsnummer | 43971 |
| Dokumenttyp | Zeitschriftenartikel |
| Peer Review | mit Peer Review |
| Sprache | Englisch |
| Titel | Inspecting adversarial examples using the Fisher information |
| Autor(in); Institution |
Martin, Jörg; 8.4, Mathematische Modellierung und Datenanalyse, PTB-Berlin
Elster, Clemens; 8.4, Mathematische Modellierung und Datenanalyse, PTB-Berlin
|
| Quelle/Jahr | Neurocomputing: 382 (2020), 80 - 86 |
| ISSN | 0925-2312 (PRINT) ; 1872-8286 (ONLINE) |
| DOI | |
| Verlag | Amsterdam [u.a.]: Elsevier |
| Freie Schlagworte | Deep Learning ; Adversarial Examples ; Fisher information ; Explainability |
| Zusammenfassung | Adversarial examples are constructed by slightly perturbing a correctly processed input to a trained neural network such that the network produces an incorrect result. This work proposes the usage of the Fisher information for the detection of such adversarial attacks. We discuss various quantities whose computation scales well with the network size, study their behavior on adversarial examples and show how they can highlight the importance of single input neurons, thereby providing a visual tool for further analyzing the behavior of a neural network. The potential of our methods is demonstrated by applications to the MNIST, CIFAR10 and Fruits-360 datasets and through comparison to concurring methods. |
| Themenbereich der Metrologie | Mathematik und metrologische Informationstechnik |