GraphRectify: Graph-Based Transfer of Adversarial Example Detectors Across Neural Networks
We propose GraphRectify, a graph-based framework for transferring adversarial image detectors across classifier backbones.
ProofPaper ↗
Key points
- Adversarial example detectors are often tied to the classifier backbone they were trained on, limiting reuse when the protected model is replaced or upgraded.
- GraphRectify learns a structured representation of intermediate classifier features and adapts representations from a new backbone to the detector learned on the original model, enabling detector reuse.
- We evaluate GraphRectify across multiple datasets, backbone architectures, and adversarial attacks, including detector-aware adaptive attacks that jointly target the classifier and detector.
- These results show that adversarial detection knowledge can transfer effectively across heterogeneous classifier architectures rather than being relearned whenever the protected backbone changes.
Sources (1)
- [1]GraphRectify: Graph-Based Transfer of Adversarial Example Detectors Across Neural NetworksarXiv (AI, ML, NLP, CV, robotics, multi-agent) · Oct 7, 05:03 PM
We propose GraphRectify, a graph-based framework for transferring adversarial image detectors across classifier backbones.
Adversarial example detectors are often tied to the classifier backbone they were trained on, limiting reuse when the protected model is replaced or upgraded.
Extractive summary: sentences quoted from the sources.