Enhancing adversarial robustness for deep metric learning via neural discrete adversarial training

被引:0
|
作者
Li, Chaofei
Zhu, Ziyuan [1 ]
Niu, Ruicheng
Zhao, Yuting
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100095, Peoples R China
关键词
Deep metric learning; Neural discrete learning; Adversarial security;
D O I
10.1016/j.cose.2024.103899
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to the security concerns arising from adversarial vulnerability in deep metric learning models, it is essential to enhance their adversarial robustness for secure neural network software development. Existing defense strategies utilize adversarial triplets to enhance adversarial robustness but sacrifice benign performance. This paper proposes a novel framework for enhancing adversarial robustness and maintaining benign performance by introducing the concept of Neural Discrete Adversarial Training (NDAT) for deep metric learning. NDAT employs VQGAN to transform the adversarial triplets into discrete inputs and then minimizes metric loss function on discrete adversarial triplets. NDAT aligns discrete adversarial examples more closely with clean samples, significantly reducing distribution deviation from their clean counterparts. Moreover, the visual explanations reveal that NDAT maintains consistent attention maps between benign and adversarial triplets and concentrates on structure details and object location perturbations. To demonstrate the effectiveness of our approach, we combine NDAT with popular adversarial methods under various perturbation iterations and intensities. Experiment evaluations on three benchmark databases illustrate that our proposed framework for deep metric learning significantly outperforms state-of-the-art defense approaches in terms of both adversarial robustness and benign performance.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Enhancing Adversarial Robustness for Deep Metric Learning
    Zhou, Mo
    Patel, Vishal M.
    [J]. 2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15304 - 15313
  • [2] Advancing Deep Metric Learning With Adversarial Robustness
    Singh, Inderjeet
    Kakizaki, Kazuya
    Araki, Toshinori
    [J]. ASIAN CONFERENCE ON MACHINE LEARNING, VOL 222, 2023, 222
  • [3] Enhancing Adversarial Robustness for Deep Metric Learning via Attention-Aware Knowledge Guidance
    Li, Chaofei
    Zhu, Ziyuan
    Pan, Yuedong
    Niu, Ruicheng
    Zhao, Yuting
    [J]. ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT XII, ICIC 2024, 2024, 14873 : 103 - 117
  • [4] Enhancing the Robustness of Deep Neural Networks by Meta-Adversarial Training
    Chang, You-Kang
    Zhao, Hong
    Wang, Wei-Jie
    [J]. International Journal of Network Security, 2023, 25 (01) : 122 - 130
  • [5] Enhancing Adversarial Robustness via Anomaly-aware Adversarial Training
    Tang, Keke
    Lou, Tianrui
    He, Xu
    Shi, Yawen
    Zhu, Peican
    Gu, Zhaoquan
    [J]. KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT I, KSEM 2023, 2023, 14117 : 328 - 342
  • [6] Metric Learning for Adversarial Robustness
    Mao, Chengzhi
    Zhong, Ziyuan
    Yang, Junfeng
    Vondrick, Carl
    Ray, Baishakhi
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [7] Improving the Robustness of Deep Neural Networks via Adversarial Training with Triplet Loss
    Li, Pengcheng
    Yi, Jinfeng
    Zhou, Bowen
    Zhang, Lijun
    [J]. PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2019, : 2909 - 2915
  • [8] On the Robustness of Metric Learning: An Adversarial Perspective
    Huai, Mengdi
    Zheng, Tianhang
    Miao, Chenglin
    Yao, Liuyi
    Zhang, Aidong
    [J]. ACM TRANSACTIONS ON KNOWLEDGE DISCOVERY FROM DATA, 2022, 16 (05)
  • [9] Deep Adversarial Metric Learning
    Duan, Yueqi
    Zheng, Wenzhao
    Lin, Xudong
    Lu, Jiwen
    Zhou, Jie
    [J]. 2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2018, : 2780 - 2789
  • [10] Deep Adversarial Metric Learning
    Duan, Yueqi
    Lu, Jiwen
    Zheng, Wenzhao
    Zhou, Jie
    [J]. IEEE TRANSACTIONS ON IMAGE PROCESSING, 2020, 29 (01) : 2037 - 2051