Toward Trustworthy Machine Learning: An Example in Defending against Adversarial Patch Attacks (2)
Freedom to Tinker 2022-07-19
Summary:
By Chong Xiang and Prateek Mittal In our previous post, we discussed adversarial patch attacks and presented our first defense algorithm PatchGuard. The PatchGuard framework (small receptive field + secure aggregation) has become the most popular defense strategy over the past year, subsuming a long list of defense instances (Clipped BagNet, De-randomized Smoothing, BagCert, Randomized […]