Wooram Jang , Woojin Hwang , Kezhong Jin , Hosung Park
{"title":"Bit flipping-based error correcting output code construction for adversarial robustness of neural networks","authors":"Wooram Jang , Woojin Hwang , Kezhong Jin , Hosung Park","doi":"10.1016/j.icte.2025.02.002","DOIUrl":null,"url":null,"abstract":"<div><div>In this paper, we propose a method for constructing error-correcting output codes (ECOCs) based on a codeword bit flipping algorithm to enhance adversarial robustness of neural networks. In the previous work in Verma and Swami (2019), ECOCs are applied to deep neural networks (DNNs) based on the analogy between channel noise and adversarial examples to achieve state-of-the-art adversarial robustness. To improve adversarial robustness, it was proposed in Wan et al. (2022) to optimize the Hamming distance between codewords and employ codeword assignment algorithms. Our study achieves approximately a 8% accuracy improvement on MNIST and CIFAR-10 under adversarial attacks compared to the method proposed in Wan et al. (2022).</div></div>","PeriodicalId":48526,"journal":{"name":"ICT Express","volume":"11 2","pages":"Pages 348-353"},"PeriodicalIF":4.1000,"publicationDate":"2025-02-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ICT Express","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2405959525000128","RegionNum":3,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
In this paper, we propose a method for constructing error-correcting output codes (ECOCs) based on a codeword bit flipping algorithm to enhance adversarial robustness of neural networks. In the previous work in Verma and Swami (2019), ECOCs are applied to deep neural networks (DNNs) based on the analogy between channel noise and adversarial examples to achieve state-of-the-art adversarial robustness. To improve adversarial robustness, it was proposed in Wan et al. (2022) to optimize the Hamming distance between codewords and employ codeword assignment algorithms. Our study achieves approximately a 8% accuracy improvement on MNIST and CIFAR-10 under adversarial attacks compared to the method proposed in Wan et al. (2022).
期刊介绍:
The ICT Express journal published by the Korean Institute of Communications and Information Sciences (KICS) is an international, peer-reviewed research publication covering all aspects of information and communication technology. The journal aims to publish research that helps advance the theoretical and practical understanding of ICT convergence, platform technologies, communication networks, and device technologies. The technology advancement in information and communication technology (ICT) sector enables portable devices to be always connected while supporting high data rate, resulting in the recent popularity of smartphones that have a considerable impact in economic and social development.