14. “They say that the best weapon
is the one you never have to fire.
I respectfully disagree.
I prefer the weapon
you only have to fire ONCE.”
-Tony Stark-
19. Defenses so far…
• Training on adversarial examples
• Generative pretraining
• Dropout
• Various non-linear units
• ….
FAILED
Direct Modification
to the network itself
33. 9
10
11
• Generate attack sets
• Tensorboard wrapping
• Analyze failed defense strategies
• Implement adversarial attacks
• Research state-of-art VAEs
• Train the VAE and test on CNN models
• Analyze and improve the algorithm
• Final presentation
• Final report
Outline plan