arXiv (Cornell University)
Towards Black-box Adversarial Example Detection: A Data Reconstruction-based Method
June 2023 • Yifei Gao, Zhiyu Lin, Yunfan Yang, Jitao Sang
Adversarial example detection is known to be an effective adversarial defense method. Black-box attack, which is a more realistic threat and has led to various black-box adversarial training-based defense methods, however, does not attract considerable attention in adversarial example detection. In this paper, we fill this gap by positioning the problem of black-box adversarial example detection (BAD). Data analysis under the introduced BAD settings demonstrates (1) the incapability of existing detectors in addres…