In plain words: It gathers the strongest known ways to protect AI systems from adversarial examples—tiny input changes that make them give wrong answers—and reviews how well each holds up. The overview ends with concrete recommendations for where future research should focus.
Abstract · Defense Against the Dark Arts: An overview of adversarial example security research and future research directions
This article presents a summary of a keynote lecture at the Deep Learning Security workshop at IEEE Security and Privacy 2018. This lecture summarizes the state of the art in defenses against adversarial examples and provides recommendations for future research directions on this topic.
Ian Goodfellow
arXiv:1806.04169 · cs.LG, cs.AI, cs.CR, stat.ML · submitted Jun 11, 2018
abstract · pdf · html