Back to results

University of Ontario Institute of Technology

Design and evaluation of GAN-based models for adversarial training robustness in deep learning

Abstract

dc:description.abstract

Adversarial attacks show one of the generalization issues of current deep learning models on special distribution shifted data. The adversarial samples generated by the attack algorithm can introduce malicious behavior to any deep learning system that affects the consistency of the deep learning model. This thesis presents the design and evaluation of multiple possible component architectures of a GAN that can provide a new direction for training a robust convolution classifier. Each component is related to a different aspect of the GAN that impacts the generalization and the robustness outcomes. The best formulation can achieve around 45% accuracy under 8/255 L∞ PGD attack and 60% accuracy under 128/255 L2 PGD attack that outperforms L2 PGD adversarial training. The other contributions include the research on gradient masking, robustness transferability across the constraints and the generalization limitations.

Degree

thesis:*
Name thesis:degree_name
Master of Applied Science (MASc)
Discipline thesis:degree_discipline
Electrical and Computer Engineering
Grantor
University of Ontario Institute of Technology
Year dc:date.issued
2023

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Zhao, Weimin
Advisors dc:contributor.advisor
  • Mahmoud, Qusay H.
  • Alwidian, Sanaa

Subjects

dc:subject × 5

Rights

Language dc:language.iso
en

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/10155/1604
OAI identifier oai:identifier
oai:ontariotechu.scholaris.ca:10155/1604

Chain of custody

source
Harvested from
Ontario Institute of Technology
Base URL
ontariotechu.scholaris.ca/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Zhao, Weimin. Design and evaluation of GAN-based models for adversarial training robustness in deep learning. University of Ontario Institute of Technology, 2023. https://hdl.handle.net/10155/1604