Feature Denoising for Improving Adversarial Robustness
Branch: master
Clone or download
Latest commit c704ef7 Feb 11, 2019


Feature Denoising for Improving Adversarial Robustness

Code and models for the paper Feature Denoising for Improving Adversarial Robustness.


By combining large-scale adversarial training and feature-denoising layers, we developed ImageNet classifiers with strong adversarial robustness.

Trained on 128 GPUs, our ImageNet classifier has 42.6% accuracy against an extremely strong 2000-steps white-box PGD targeted attack. This is a scenario where no previous models have achieved more than 1% accuracy.

On black-box adversarial defense, our method won the champion of defense track in the CAAD (Competition of Adversarial Attacks and Defenses) 2018. It also greatly outperforms the CAAD 2017 defense track winner when evaluated against CAAD 2017 black-box attackers.

This repo contains:

  1. Our trained models, together with the evaluation script to verify their robustness. We welcome attackers to attack our released models and defenders to compare with our released models.

  2. Our distributed adversarial training code on ImageNet.

Please see INSTRUCTIONS.md for the usage.


This project is under the CC-BY-NC 4.0 license. See LICENSE for details.


If you use our code, models or wish to refer to our results, please use the following BibTex entry:

	title={Feature denoising for improving adversarial robustness},
	author={Xie, Cihang and Wu, Yuxin and van der Maaten, Laurens and Yuille, Alan and He, Kaiming},
	journal={arXiv preprint arXiv:1812.03411},