%PDF-1.3 1 0 obj << /Kids [ 3 0 R 4 0 R 5 0 R 6 0 R 7 0 R 8 0 R 9 0 R 10 0 R 11 0 R 12 0 R ] /Type /Pages /Count 10 >> endobj 2 0 obj << /Title (Defense Against Adversarial Attacks Using High\055Level Representation Guided Denoiser) /Producer (PyPDF2) /Author (Fangzhou Liao\054 Ming Liang\054 Yinpeng Dong\054 Tianyu Pang\054 Xiaolin Hu\054 Jun Zhu) /Subject (2018 IEEE Conference on Computer Vision and Pattern Recognition) >> endobj 3 0 obj << /Parent 1 0 R /Rotate 0 /Contents 14 0 R /Resources << /XObject << /x8 15 0 R /R36 18 0 R /x6 20 0 R /R35 19 0 R /x12 23 0 R /x10 26 0 R >> /ExtGState << /s9 29 0 R /s11 32 0 R /a0 << /CA 1 /ca 1 >> /R19 35 0 R /s5 36 0 R /s7 39 0 R >> /Font << /F2 42 0 R /R28 43 0 R /F1 47 0 R /R20 48 0 R /R22 52 0 R /R32 56 0 R /R24 59 0 R /R30 63 0 R /R26 67 0 R >> /ProcSet [ /Text /ImageC /ImageB /PDF /ImageI ] >> /Group 71 0 R /MediaBox [ 0 0 612 792 ] /Annots [ 72 0 R 73 0 R 74 0 R 75 0 R 76 0 R 77 0 R 78 0 R 79 0 R 80 0 R ] /Type /Page >> endobj 4 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 81 0 R /Resources << /ExtGState << /R19 35 0 R >> /Font << /R79 82 0 R /R73 86 0 R /R71 90 0 R /R77 95 0 R /R75 98 0 R /F2 103 0 R /F1 104 0 R /R20 48 0 R /R81 105 0 R /R22 52 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 109 0 R 110 0 R 111 0 R 112 0 R 113 0 R 114 0 R 115 0 R 116 0 R 117 0 R 118 0 R 119 0 R 120 0 R 121 0 R 122 0 R 123 0 R 124 0 R 125 0 R 126 0 R 127 0 R 128 0 R 129 0 R 130 0 R 131 0 R 132 0 R 133 0 R 134 0 R 135 0 R 136 0 R ] >> endobj 5 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 137 0 R /Resources << /XObject << /R118 138 0 R /R119 139 0 R >> /ExtGState << /R19 35 0 R >> /Font << /F2 140 0 R /R71 90 0 R /R79 82 0 R /R73 86 0 R /R20 48 0 R /F1 141 0 R /R22 52 0 R /R116 142 0 R /R75 98 0 R >> /ProcSet [ /Text /ImageC /ImageB /PDF /ImageI ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 145 0 R 146 0 R 147 0 R 148 0 R 149 0 R 150 0 R 151 0 R 152 0 R 153 0 R 154 0 R 155 0 R 156 0 R 157 0 R 158 0 R 159 0 R 160 0 R 161 0 R 162 0 R 163 0 R 164 0 R 165 0 R 166 0 R 167 0 R 168 0 R 169 0 R 170 0 R 171 0 R ] >> endobj 6 0 obj << /Parent 1 0 R /Rotate 0 /Contents 172 0 R /Resources << /XObject << /R136 173 0 R /R137 174 0 R >> /ExtGState << /R19 35 0 R >> /Font << /R79 82 0 R /R73 86 0 R /R71 90 0 R /R116 142 0 R /R77 95 0 R /R75 98 0 R /F2 175 0 R /F1 176 0 R /R20 48 0 R /R22 52 0 R >> /ProcSet [ /Text /ImageC /ImageB /PDF /ImageI ] >> /Group 71 0 R /MediaBox [ 0 0 612 792 ] /Annots [ 177 0 R 178 0 R 179 0 R 180 0 R 181 0 R 182 0 R 183 0 R 184 0 R 185 0 R 186 0 R ] /Type /Page >> endobj 7 0 obj << /Parent 1 0 R /Rotate 0 /Contents 187 0 R /Resources << /XObject << /R162 188 0 R /R161 189 0 R /R160 190 0 R /R157 192 0 R /R158 193 0 R /R159 191 0 R >> /ExtGState << /R19 35 0 R >> /Font << /R163 194 0 R /F2 199 0 R /R71 90 0 R /R73 86 0 R /F1 200 0 R /R20 48 0 R /R75 98 0 R /R22 52 0 R /R26 67 0 R >> /ProcSet [ /Text /ImageC /ImageB /PDF /ImageI ] >> /Group 201 0 R /MediaBox [ 0 0 612 792 ] /Annots [ 202 0 R 203 0 R 204 0 R 205 0 R 206 0 R 207 0 R 208 0 R 209 0 R 210 0 R 211 0 R 212 0 R 213 0 R ] /Type /Page >> endobj 8 0 obj << /Parent 1 0 R /Rotate 0 /Contents 214 0 R /Resources << /XObject << /R228 215 0 R /R202 218 0 R /R200 219 0 R /R201 220 0 R /R185 221 0 R /R184 222 0 R /R187 223 0 R /R180 224 0 R /R220 225 0 R /R221 226 0 R /R222 227 0 R /R223 228 0 R /R224 229 0 R /R225 230 0 R /R226 231 0 R /R227 232 0 R /R191 233 0 R /R196 234 0 R /R197 235 0 R /R194 236 0 R /R209 237 0 R /R181 238 0 R /R216 239 0 R /R188 240 0 R /R208 241 0 R /R211 242 0 R /R193 243 0 R /R213 244 0 R /R212 245 0 R /R215 246 0 R /R214 247 0 R /R217 248 0 R /R238 249 0 R /R219 250 0 R /R218 251 0 R /R199 252 0 R /R253 253 0 R /R190 254 0 R >> /ExtGState << /R19 35 0 R /R178 216 0 R >> /Font << /R163 194 0 R /R183 255 0 R /R22 52 0 R /R73 86 0 R /R176 295 0 R /R71 90 0 R /R116 142 0 R /R77 95 0 R /R75 98 0 R /F2 298 0 R /F1 299 0 R /R233 283 0 R /R20 48 0 R /R230 287 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /Group 294 0 R /MediaBox [ 0 0 612 792 ] /Annots [ 300 0 R 301 0 R 302 0 R 303 0 R 304 0 R ] /Type /Page >> endobj 9 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 305 0 R /Resources << /ExtGState << /R19 35 0 R >> /Font << /R163 194 0 R /R79 82 0 R /R73 86 0 R /R176 295 0 R /R71 90 0 R /R75 98 0 R /F2 306 0 R /F1 307 0 R /R20 48 0 R /R22 52 0 R /R32 56 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ 308 0 R 309 0 R 310 0 R 311 0 R 312 0 R 313 0 R 314 0 R 315 0 R 316 0 R 317 0 R 318 0 R 319 0 R 320 0 R 321 0 R 322 0 R ] >> endobj 10 0 obj << /Parent 1 0 R /Rotate 0 /Contents 323 0 R /Resources << /XObject << /R361 324 0 R /R360 325 0 R /R363 326 0 R /R362 327 0 R /R365 328 0 R /R364 329 0 R /R367 330 0 R /R366 331 0 R /R369 332 0 R /R368 333 0 R /R329 334 0 R /R325 335 0 R /R324 336 0 R /R321 337 0 R /R320 338 0 R /R323 339 0 R /R322 340 0 R /R282 341 0 R /R280 342 0 R /R285 343 0 R /R372 344 0 R /R373 345 0 R /R370 346 0 R /R371 347 0 R /R376 348 0 R /R377 349 0 R /R374 350 0 R /R375 351 0 R /R378 352 0 R /R379 353 0 R /R338 354 0 R /R339 355 0 R /R336 356 0 R /R337 357 0 R /R334 358 0 R /R335 359 0 R /R332 360 0 R /R333 361 0 R /R330 362 0 R /R331 363 0 R /R358 364 0 R /R315 365 0 R /R344 366 0 R /R342 367 0 R /R341 368 0 R /R340 369 0 R /R309 370 0 R /R308 371 0 R /R302 372 0 R /R301 373 0 R /R307 374 0 R /R306 376 0 R /R305 377 0 R /R382 402 0 R /R354 411 0 R /R314 404 0 R /R359 406 0 R /R316 407 0 R /R317 415 0 R /R310 417 0 R /R311 403 0 R /R350 408 0 R /R351 409 0 R /R352 405 0 R /R353 410 0 R /R318 416 0 R /R319 412 0 R /R356 413 0 R /R355 414 0 R /R357 418 0 R /R299 378 0 R /R298 379 0 R /R291 384 0 R /R293 385 0 R /R292 380 0 R /R295 381 0 R /R294 382 0 R /R297 383 0 R /R296 375 0 R >> /ExtGState << /R19 35 0 R /R178 216 0 R >> /Font << /R71 90 0 R /R313 434 0 R /R73 86 0 R /F1 437 0 R /R281 391 0 R /R343 423 0 R /R287 393 0 R /R284 396 0 R /F2 438 0 R /R79 82 0 R /R116 142 0 R /R290 386 0 R /R20 48 0 R /R327 419 0 R /R22 52 0 R /R328 431 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /Group 294 0 R /MediaBox [ 0 0 612 792 ] /Annots [ 439 0 R ] /Type /Page >> endobj 11 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 440 0 R /Resources << /ExtGState << /R19 35 0 R >> /Font << /F2 441 0 R /R28 43 0 R /F1 442 0 R /R22 52 0 R /R20 48 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ ] >> endobj 12 0 obj << /Parent 1 0 R /Rotate 0 /Type /Page /Contents 443 0 R /Resources << /ExtGState << /R19 35 0 R >> /Font << /F2 444 0 R /R28 43 0 R /F1 445 0 R /R22 52 0 R >> /ProcSet [ /ImageC /Text /PDF /ImageI /ImageB ] >> /MediaBox [ 0 0 612 792 ] /Annots [ ] >> endobj 13 0 obj << /Type /Catalog /Pages 1 0 R >> endobj 14 0 obj << /Length 12817 >> stream q q q 0.1 0 0 0.1 0 0 cm /R19 gs 0 g q 10 0 0 10 0 0 cm BT /R20 14.3462 Tf 1 0 0 1 167.386 675.067 Tm [ (Defense) -250.013 (against) -249.998 (Adv) 10.0014 (ersarial) -250.012 (Attacks) -250.012 (Using) ] TJ -5.55195 -17.9332 Td [ (High\055Le) 14.9927 (v) 9.99625 (el) -250.002 (Repr) 18.0014 (esentation) -250.013 (Guided) -249.99 (Denoiser) ] TJ /R22 11.9552 Tf -54.6852 -37.8578 Td [ (F) 15.0158 (angzhou) -249.995 (Liao) ] TJ /R24 7.9701 Tf 71.8742 4.33867 Td [ <03> -0.29866 ] TJ /R22 11.9552 Tf 4.33867 TL T* [ (\054) -250.012 (Ming) -250 (Liang) ] TJ /R24 7.9701 Tf 62.7641 4.33867 Td [ <03> -0.30019 ] TJ /R22 11.9552 Tf T* [ (\054) -250.012 (Y) 54.9925 (inpeng) -250 (Dong\054) -250.012 (T) 34.9898 (ian) 14.9872 (yu) -250.012 (P) 15.0158 (ang\054) -250.01 (Xiaolin) -249.989 (Hu) ] TJ /R24 7.9701 Tf 201.456 4.33867 Td [ (y) -0.20217 ] TJ /R22 11.9552 Tf T* [ (\054) -250.01 (Jun) -249.997 (Zhu) ] TJ -363.793 -13.9473 Td [ (Department) -250 (of) -250.015 (Computer) -250.014 (Science) -250.006 (and) -249.987 (T) 70.0164 (echnology) 65.0132 (\054) -250.012 (Tsinghua) -249.989 (Lab) -250.014 (of) -250.014 (Brain) -249.989 (and) -249.985 (Intelligence\054) ] TJ 7.96211 -13.948 Td [ (Beijing) -250 (National) -250 (Research) -250.006 (Center) -249.997 (for) -249.995 (Information) -250.004 (Science) -250.006 (and) -249.987 (T) 70.0164 (echnology) 65.0132 (\054) -250.01 (BNRist) -250.006 (Lab) ] TJ 125.151 -13.9477 Td [ (Tsinghua) -249.989 (Uni) 24.9957 (v) 14.9851 (ersity) 64.9887 (\054) -250.012 (100084) -249.991 (China) ] TJ /R26 8.9664 Tf -135.004 -13.9473 Td [ (f) -0.8999 ] TJ /R22 8.9664 Tf 4.6082 0 Td [ (liaof) 10.0051 (angzhou\054) -249.996 (liangming\056tsinghua) ] TJ /R26 8.9664 Tf 120.202 0 Td [ (g) -0.90126 ] TJ /R22 8.9664 Tf 4.60781 0 Td (\100gmail\056com\054) Tj /R26 8.9664 Tf 50.848 0 Td [ (f) -0.90126 ] TJ /R22 8.9664 Tf 4.60703 0 Td [ (dyp17\054) -250.003 (pty17) ] TJ /R26 8.9664 Tf 47.325 0 Td [ (g) -0.90126 ] TJ /R22 8.9664 Tf 4.60781 0 Td (\100mails\056tsinghua\056edu\056cn\054) Tj /R26 8.9664 Tf 90.6941 0 Td [ (f) -0.89854 ] TJ /R22 8.9664 Tf 4.60703 0 Td [ (xlhu\054) -249.995 (dcszj) ] TJ /R26 8.9664 Tf 38.8512 0 Td [ (g) -0.89854 ] TJ /R22 8.9664 Tf 4.60781 0 Td (\100tsinghua\056edu\056cn) Tj /R20 11.9552 Tf -307.13 -41.0461 Td (Abstract) Tj /R28 9.9626 Tf -83.9277 -24.207 Td [ (Neur) 14.9981 (al) -209.012 (networks) -208.009 (ar) 36.9852 (e) -208.99 (vulner) 14.9926 (able) -207.992 (to) -209.012 (adver) 10.0057 (sarial) -208.987 (e) 19.9918 (xamples\054) ] TJ -11.9551 -11.9547 Td [ (whic) 14.9987 (h) -307.003 (poses) -308.009 (a) -307.003 (thr) 36.9926 (eat) -307 (to) -308.015 (their) -306.987 (application) -306.993 (in) -306.995 (security) -308.007 (sensi\055) ] TJ 11.9551 TL T* [ (tive) -322.019 (systems\056) -526.988 (W) 91.9859 (e) -321.99 (pr) 44.9839 (opose) -322.008 (high\055le) 15 (vel) -323.006 (r) 37.0196 (epr) 38.001 (esentation) -323.005 (guided) ] TJ T* [ (denoiser) -216.997 (\050HGD\051) -216.981 (as) -217.992 (a) -217.018 (defense) -217.013 (for) -217.004 (ima) 10.013 (g) 10.0032 (e) -218.008 <636c6173736902636174696f6e2e> -298.989 (Stan\055) ] TJ 11.9559 TL T* [ (dar) 36.9902 (d) -273.008 (denoiser) -274.007 (suf) 18.0154 (fer) 10.0069 (s) -273.007 (fr) 44.9864 (om) -273.006 (the) -273.986 (err) 44.9802 (or) -273.002 <616d706c6902636174696f6e> -272.996 (ef) 18 (fect\054) -279.985 (in) ] TJ 11.9551 TL T* [ (whic) 14.9987 (h) -243.013 (small) -242.99 (r) 37.0196 (esidual) -242.988 (adver) 10.0057 (sarial) -242.982 (noise) -244.019 (i) 0.98758 (s) -243.994 (pr) 44.9851 (o) 10.0032 (gr) 36.9865 (essively) -243.008 (am\055) ] TJ T* [ <706c69026564> -270.988 (and) -272.018 (leads) -270.995 (to) -271.001 (wr) 44.9925 (ong) -272.018 (class) 1 <6902636174696f6e732e> -374.009 (HGD) -271.986 (o) 10.0032 (ver) 37.011 (comes) ] TJ T* [ (this) -306.982 (pr) 44.9839 (oblem) -308.011 (by) -307.006 (using) -307.999 (a) -307.003 (loss) -308.003 (function) -307.01 <6465026e6564> -308.015 (as) -306.995 (the) -308.02 (dif) 18.0166 (fer) 20.0065 (\055) ] TJ T* [ (ence) -391.982 (between) -391.996 (the) -392.986 (tar) 36.9926 (g) 10.0032 (et) -392.011 (model\047) 40.0056 (s) -392.007 (outputs) -392.011 (activated) -391.988 (by) -392.993 (the) ] TJ T* [ (clean) -245.009 (ima) 10.0136 (g) 10.0032 (e) -246.002 (and) -245.003 (denoised) -244.993 (ima) 10.013 (g) 10.0032 (e) 15.0122 (\056) -309.005 (Compar) 37.011 (ed) -245.018 (with) -246.006 (ensemble) ] TJ 11.9559 TL T* [ (adver) 10.0057 (sarial) -273.996 (tr) 14.9914 (aining) -273.998 (whic) 14.9987 (h) -273.008 (is) -274.019 (the) -273.986 (state\055of\055the\055art) -273.984 (defending) ] TJ 11.9551 TL T* [ (method) -258.015 (on) -259.006 (lar) 36.9926 (g) 10.0032 (e) -258.001 (ima) 10.013 (g) 10.0032 (es\054) -259.992 (HGD) -257.988 (has) -259 (thr) 36.9926 (ee) -258.006 (advanta) 9.98608 (g) 10.0032 (es\056) -334.998 (F) 45.017 (ir) 10.0106 (st\054) ] TJ T* [ (with) -293.017 (HGD) -293.001 (as) -292.999 (a) -293.005 (defense) 10.0081 (\054) -303.986 (the) -293.003 (tar) 36.9926 (g) 10.0032 (et) -293.007 (model) -292.995 (is) -294.017 (mor) 38.0084 (e) -293.995 (r) 45.017 (ob) 20.0065 (ust) -292.993 (to) ] TJ T* [ (either) -282.995 (white\055box) -282.981 (or) -281.981 (blac) 20.0089 (k\055box) -283.014 (adver) 10.0057 (sarial) -283.014 (attac) 20.0163 (ks\056) -408.986 (Second\054) ] TJ T* [ (HGD) -346.012 (can) -346.015 (be) -345.981 (tr) 14.9914 (ained) -346.002 (on) -346.011 (a) -346.016 (small) -345.992 (subset) -345.996 (of) -346.008 (the) -346.013 (ima) 10.013 (g) 10.0032 (es) -346.018 (and) ] TJ T* [ (g) 10.0032 (ener) 15.0196 (alizes) -244.011 (well) -244.995 (to) -243.986 (other) -244.019 (ima) 10.013 (g) 10.0032 (es) -245.017 (and) -243.984 (unseen) -245.006 (classes\056) -308.003 (Thir) 37.0061 (d\054) ] TJ 11.9563 TL T* [ (HGD) -368.989 (can) -370.011 (be) -368.996 (tr) 14.9914 (ansferr) 37.0049 (ed) -368.996 (to) -368.985 (defend) -370.003 (models) -369.014 (other) -369.017 (than) -369.995 (the) ] TJ 11.9547 TL T* [ (one) -265.009 (guiding) -265.015 (it\056) -354.982 (In) -265.013 (NIPS) -264.996 (competition) -265.011 (on) -265.005 (defense) -265.005 (a) 10.0032 (gainst) -265.02 (ad\055) ] TJ T* [ (ver) 9.99588 (sarial) -240.982 (attac) 20.0163 (ks\054) -243.015 (our) -241.003 (HGD) -241.01 (solution) -241.01 (won) -240.997 (the) -241.011 <0272> 10.0106 (st) -241.006 (place) -241.011 (and) ] TJ T* [ (outperformed) -249.991 (other) -250.018 (models) -250.015 (by) -249.996 (a) -249.993 (lar) 36.9926 (g) 10.0032 (e) -250.002 (mar) 36.9889 (gin\056) ] TJ /R22 6.9738 Tf 187.375 3.61484 Td (1) Tj /R20 11.9552 Tf -187.375 -40.3687 Td [ (1\056) -249.99 (Intr) 18.0146 (oduction) ] TJ /R22 9.9626 Tf 11.9551 -19.225 Td [ (As) -263.986 (man) 14.9908 (y) -263.99 (other) -263.985 (machine) -264.999 (learning) -264.017 (models) -264.003 (\1332\135\054) -267.995 (neural) -263.99 (net\055) ] TJ -11.9551 -11.9551 Td [ (w) 10.0014 (orks) -312.994 (are) -313.998 (kno) 24.9909 (wn) -313 (to) -312.994 (be) -313.986 (vulnerable) -312.988 (to) -312.994 (adv) 14.9828 (ersarial) -313.987 (e) 15.0122 (xamples) ] TJ T* [ (\13330\054) -279.983 (7\135\056) -400.988 (Adv) 14.9908 (ersarial) -279.991 (e) 15.0122 (xamples) -280.005 (are) -280.005 (maliciously) -280.997 (des) 0.98758 (igned) -280.995 (in\055) ] TJ 11.9559 TL T* [ (puts) -224.018 (to) -223.009 (attack) -223.996 (a) -224.007 (tar) 17.997 (get) -223.014 (model\056) -302.001 (The) 14.9828 (y) -223.017 (ha) 19.9979 (v) 14.9828 (e) -224.007 (small) -224.012 (perturbations) ] TJ 11.9551 TL T* [ (on) -255.987 (original) -254.987 (inputs) -256 (b) 20.0016 (ut) -255.984 (can) -254.981 (mislead) -256.006 (the) -255.989 (tar) 17.997 (get) -255.989 (model\056) -327.017 (Adv) 14.9901 (er) 19.9893 (\055) ] TJ T* [ (sarial) -330.995 (e) 15.0128 (xamples) -331.016 (can) -331.007 (be) -331.002 (transferred) -331.006 (across) -330.999 (dif) 24.986 (ferent) -331.006 (models) ] TJ T* [ (\13330\054) -364.989 (21\135\056) -653.019 (This) -365.015 (transferability) -365.003 (enables) -364.008 (black\055box) -365.018 (adv) 14.9828 (ersar) 19.9869 (\055) ] TJ T* [ (ial) -362.988 (attacks) -364.005 (without) -362.998 (kno) 24.9909 (wing) -363.998 (the) -362.991 (weights) -363.988 (and) -362.993 (structures) -363.996 (of) ] TJ T* [ (the) -265.987 (tar) 17.9964 (get) -267.006 (model\056) -359.011 (Black\055box) -266.986 (attacks) -265.983 (ha) 19.9967 (v) 14.9828 (e) -266 (been) -267.012 (sho) 24.9934 (wn) -265.987 (to) -267.002 (be) ] TJ ET Q 3.98 w 0 G 501.121 1099.47 m 1446.11 1099.47 l S q 10 0 0 10 0 0 cm BT /R30 5.9776 Tf 1 0 0 1 60.141 103.345 Tm [ <03> -0.90058 ] TJ /R22 7.9701 Tf 4.3168 -2.81289 Td [ (Equal) -249.994 (contrib) 19.9966 (ution\056) ] TJ /R30 5.9776 Tf -3.92969 -6.98984 Td [ (y) -0.10006 ] TJ /R22 7.9701 Tf 3.92969 -2.81328 Td [ (Corresponding) -250 (author) 54.9815 (\056) ] TJ /R22 5.9776 Tf -3.48672 -6.91602 Td (1) Tj /R22 7.9701 Tf 3.48672 -2.81289 Td (Code\072) Tj /R32 7.9701 Tf 21.5113 0 Td [ (https\072\057\057github\056com\057lfz\057Guided\055) -63.0194 (Denoise) ] TJ /R22 7.9701 Tf 177.435 0 Td (\056) Tj ET Q q 2362.56 0 0 1970.83 3088.62 3353.21 cm /R36 Do Q q 10 0 0 10 0 0 cm BT /R22 9.9626 Tf 1 0 0 1 308.862 316.99 Tm [ (Figure) -308.983 (1\072) -427.995 (The) -309.002 (idea) -309.005 (of) -309.005 (high\055le) 24.9958 (v) 14.9828 (el) -309.983 (representation) -308.983 (guided) -308.983 (de\055) ] TJ 11.9547 TL T* [ (noiser) 54.9859 (\056) -491.014 (The) -309.983 (dif) 24.986 (ference) -310.007 (between) -309.983 (the) -310.017 (original) -309.997 (image) -310.992 (and) -309.983 (ad\055) ] TJ T* [ (v) 14.9828 (ersarial) -408.991 (image) -407.996 (is) -409.018 (tin) 14.9975 (y) 65.0137 (\054) -448.001 (b) 20.0016 (ut) -409.02 (the) -408.981 (dif) 24.986 (ference) -407.991 (is) -409.015 <616d706c69026564> -408.986 (in) ] TJ 11.9559 TL T* [ (high\055le) 24.9983 (v) 14.9828 (el) -206.983 (representation) -207.98 (\050logits) -206.99 (for) -208.005 (e) 15.0122 (xample\051) -207.005 (of) -208.005 (a) -206.99 (CNN\056) -207.985 (W) 79.9866 (e) ] TJ 11.9551 TL T* [ (use) -229.993 (the) -231.013 (distance) -229.984 (o) 14.9828 (v) 14.9828 (er) -230.988 (high\055le) 24.9958 (v) 14.9828 (el) -229.996 (representations) -230.991 (to) -229.991 (guide) -231 (the) ] TJ T* [ (training) -339.012 (of) -339 (an) -339.002 (image) -338.988 (denoiser) -338.988 (to) -338.992 (suppress) -339.017 (the) -338.992 <696e0375656e6365> -339.017 (of) ] TJ T* [ (adv) 14.9828 (ersarial) -249.997 (perturbation\056) ] TJ 40.9629 TL T* [ (feasible) -295 (in) -294.017 (real\055w) 9.99343 (orld) -294.995 (scenarios) -294.995 (\13322\135\054) -305.983 (which) -294.015 (poses) -294.99 (a) -295.014 (poten\055) ] TJ 11.9551 TL T* [ (tial) -362 (threat) -362.991 (to) -362.006 (security\055sensiti) 24.986 (v) 14.9828 (e) -361.984 (deep) -362.018 (learning) -362.979 (applications\054) ] TJ T* [ (such) -300.996 (as) -301.006 (identity) -301.009 (authentication) -299.984 (and) -301.004 (autonomous) -300.999 (dri) 24.986 (ving\056) -462.996 (It) ] TJ 11.9559 TL T* [ (is) -221.01 (thus) -221 (important) -220.98 (to) -221.01 <026e64> -220.997 (ef) 25.0056 (fecti) 25.0154 (v) 14.9828 (e) -220.988 (defenses) -221.017 (ag) 5.01877 (ainst) -221.002 (adv) 14.9828 (ersar) 19.9869 (\055) ] TJ 11.9551 TL T* [ (ial) -249.988 (attacks\056) ] TJ 11.9551 -15.6988 Td [ (Since) -433.989 (adv) 14.9828 (ersarial) -434.006 (e) 15.0122 (xamples) -434.021 (are) -434.016 (constructed) -435 (by) -433.996 (adding) ] TJ -11.9551 -11.9551 Td [ (noises) -355.014 (to) -354.987 (original) -355.009 (images\054) -381.99 (a) -355.004 (natural) -354.985 (idea) -354.995 (is) -354.985 (to) -356.009 (denoise) -355.019 (ad\055) ] TJ 11.9559 TL T* [ (v) 14.9828 (ersarial) -261.995 (e) 15.0122 (xamples) -262.988 (before) -262 (sending) -262.986 (them) -262.015 (to) -263.005 (the) -261.986 (tar) 17.997 (get) -263.005 (model) ] TJ 11.9551 TL T* [ (\050Figure) -211.004 (1\051\056) -297.004 (W) 79.9866 (e) -212.009 (e) 15.0122 (xplored) -211.004 (tw) 10.0081 (o) -211.019 (models) -210.994 (for) -210.984 (denoising) -212.004 (adv) 14.9828 (ersar) 19.9869 (\055) ] TJ T* [ (ial) -235.01 (e) 15.0122 (xamples\054) -238.009 (and) -235.995 (found) -235.002 (that) -235.005 (the) -235.99 (noise) -235 (le) 25.0203 (v) 14.9828 (el) -235.015 (could) -235 (indeed) -235.985 (be) ] TJ T* [ (reduced\056) -301.006 (These) -221.995 (results) -222.997 (demonstrate) -222.012 (the) -221.992 (feasibility) -222.982 (of) -222.002 (the) -223.012 (de\055) ] TJ -13.741 -29.8879 Td (1) Tj ET Q Q Q q q 1 1 1 rg /a0 gs 48.406 786.422 515.188 -52.699 re f q /s5 gs /x6 Do Q q /s7 gs /x8 Do Q q /s9 gs /x10 Do Q q /s11 gs /x12 Do Q Q Q Q q 1 0 0 1 0 0 cm BT /F1 12 Tf 14.4 TL ET 1 1 1 rg n 270 47 72 14 re f* 0.5 0.5 0.5 rg BT /F2 9 Tf 10.8 TL ET BT 1 0 0 1 297 50 Tm (1778) Tj T* ET Q endstream endobj 15 0 obj << /Filter /FlateDecode /Resources << /ExtGState << /a0 << /CA 1 /ca 1 >> >> /XObject << /x18 16 0 R >> >> /Length 28 /Group << /Type /Group /S /Transparency /CS /DeviceRGB /I true >> /BBox [ 78 746 96 765 ] /Type /XObject /Subtype /Form >> stream x+O4PH/VЯ0Pp 0 endstream endobj 16 0 obj << /Filter /FlateDecode /Resources 17 0 R /Length 107 /Type /XObject /BBox [ 78 746 96 765 ] /Subtype /Form >> stream xe AC̬wʠ =p,?]%+H-
Jc "82w8VSnGW;"
endstream
endobj
17 0 obj
<<
/ExtGState <<
/a0 <<
/CA 1
/ca 1
>>
>>
>>
endobj
18 0 obj
<<
/SMask 19 0 R
/Filter /DCTDecode
/BitsPerComponent 8
/Height 810
/Length 33072
/ColorSpace /DeviceRGB
/Width 971
/Subtype /Image
>>
stream
Adobe d C
$, !$4.763.22:ASF:=N>22HbINVX]^]8EfmeZlS[]Y C**Y;2;YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY *"
} !1AQa"q2#BR$3br
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
w !1AQaq"2B #3Rbr
$4%&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz ? j(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
(
ЏCզ$KxV[w!A"9 "֕ ^p