polito.it
Politecnico di Torino (logo)

Neural Networks for image classification - An approach to adversarial perturbation robustness

Luca Volpato

Neural Networks for image classification - An approach to adversarial perturbation robustness.

Rel. Enrico Magli. Politecnico di Torino, Corso di laurea magistrale in Communications And Computer Networks Engineering (Ingegneria Telematica E Delle Comunicazioni), 2019

[img]
Preview
PDF (Tesi_di_laurea) - Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives.

Download (3MB) | Preview
Abstract:

This thesis is the study of an alternative method for standard classification problems for neural networks, developed with the purpose of obtaining increased robustness to adversarial perturbations. ??Through the use of an encoder, the system maps its input data to distributions with arbitrarily selected target mean values, inside of a latent space with a dimensionality equal to the number of classes. The hope is that, by enforcing a great a great enough distance among the classes distributions, adversarial attacks will succed less often. ??A prototype of the system was already developed for two classes, authorized and not-authorized, and this document explores the results and methods of a multi-class implementation. ?? ??Studies were executed on the MNIST and CIFAR datasets, but the outcomes obtained are solid enough for extension to other databases. Indeed, results prove that a system such as the one presented is consistently more resistant to adversarial perturbations than a standard cross entropy scheme, while providing the same levels of accuracy when no perturbation is present.

Relatori: Enrico Magli
Anno accademico: 2019/20
Tipo di pubblicazione: Elettronica
Numero di pagine: 56
Soggetti:
Corso di laurea: Corso di laurea magistrale in Communications And Computer Networks Engineering (Ingegneria Telematica E Delle Comunicazioni)
Classe di laurea: Nuovo ordinamento > Laurea magistrale > LM-27 - INGEGNERIA DELLE TELECOMUNICAZIONI
Aziende collaboratrici: NON SPECIFICATO
URI: http://webthesis.biblio.polito.it/id/eprint/13097
Modifica (riservato agli operatori) Modifica (riservato agli operatori)