Abstract:
Extensive research on attacks on deep learning models has shown that these models are not as robust as they seem. A carefully designed low magnitude perturbation is enough to cause havoc and completely confuse the model. This project addresses this pitfall by first developing a benchmarking adversarial detection and adversary mitigation toolbox for face recognition, then by proposing a defense technique that alleviates the embedded imperceptible noise and nally by proposing a blockchain-based architecture for the deep learning models.