Enhancing Generalization in Few-Shot Learning for Detecting Unknown Adversarial Examples

被引:0
|
作者
Liu, Wenzhao [1 ,2 ]
Zhang, Wanli [1 ]
Yang, Kuiwu [1 ]
Chen, Yue [1 ]
Guo, Kaiwei [1 ]
Wei, Jianghong [1 ]
机构
[1] State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Henan, Peoples R China
[2] Natl Univ Def Technol, Environm Effects Elect & Informat Syst, State key Lab Complex Electromagnet, Changsha 471000, Hunan, Peoples R China
基金
中国国家自然科学基金; 中国博士后科学基金;
关键词
Adversarial example detection; Few-shot learning; Prototypical network; New adversarial attacks; ATTACKS; VISION;
D O I
10.1007/s11063-024-11572-6
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks, particularly convolutional neural networks, are vulnerable to adversarial examples, undermining their reliability in visual recognition tasks. Adversarial example detection is a crucial defense mechanism against such attacks but often relies on empirical observations and specialized metrics, posing challenges in terms of data efficiency, generalization to unknown attacks, and scalability to high-resolution datasets like ImageNet. To address these issues, we propose a prototypical network-based method using a deep residual network as the backbone architecture. This approach is capable of extracting discriminative features of adversarial and normal examples from various known adversarial examples by constructing few-shot adversarial detection tasks. Then the optimal mapping matrix is computed using the Sinkhorn algorithm from optimal transport theory, and the class centers are iteratively updated, enabling the detection of unknown adversarial examples across scenarios. Experimental results show that the proposed approach outperforms existing methods in the cross-adversary benchmark and achieves enhanced generalization on a subset of ImageNet in detecting both new adversarial attacks and adaptive white-box attacks. The proposed approach offers a promising solution for improving the safety of deep neural networks in practical applications.
引用
收藏
页数:25
相关论文
共 50 条
  • [1] Enhancing Generalization in Few-Shot Learning for Detecting Unknown Adversarial Examples
    Wenzhao Liu
    Wanli Zhang
    Kuiwu Yang
    Yue Chen
    Kaiwei Guo
    Jianghong Wei
    [J]. Neural Processing Letters, 56
  • [2] Federated Few-Shot Learning with Adversarial Learning
    Fan, Chenyou
    Huang, Jianwei
    [J]. 2021 19TH INTERNATIONAL SYMPOSIUM ON MODELING AND OPTIMIZATION IN MOBILE, AD HOC, AND WIRELESS NETWORKS (WIOPT), 2021,
  • [3] Detecting High-Resolution Adversarial Images with Few-Shot Deep Learning
    Zhao, Junjie
    Wu, Junfeng
    Adeke, James Msughter
    Qiao, Sen
    Wang, Jinwei
    [J]. REMOTE SENSING, 2023, 15 (09)
  • [4] MetaGAN: An Adversarial Approach to Few-Shot Learning
    Zhang, Ruixiang
    Che, Tong
    Ghahramani, Zoubin
    Bengio, Yoshua
    Song, Yangqiu
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 31 (NIPS 2018), 2018, 31
  • [5] Enhancing Few-Shot Image Classification with Unlabelled Examples
    Bateni, Peyman
    Barber, Jarred
    van de Meent, Jan-Willem
    Wood, Frank
    [J]. 2022 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV 2022), 2022, : 1597 - 1606
  • [6] Generalizing from a Few Examples: A Survey on Few-shot Learning
    Wang, Yaqing
    Yao, Quanming
    Kwok, James T.
    Ni, Lionel M.
    [J]. ACM COMPUTING SURVEYS, 2020, 53 (03)
  • [7] Learning a Universal Template for Few-shot Dataset Generalization
    Triantafillou, Eleni
    Larochelle, Hugo
    Zemel, Richard
    Dumoulin, Vincent
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 139, 2021, 139 : 7435 - 7446
  • [8] Learning to Sort: Few-shot Spike Sorting with Adversarial Representation Learning
    Wu, Tong
    Ratkai, Aniko
    Schlett, Katalin
    Grand, Laszlo
    Yang, Zhi
    [J]. 2019 41ST ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY (EMBC), 2019, : 713 - 716
  • [9] Few-Shot Adversarial Domain Adaptation
    Motiian, Saeid
    Jones, Quinn
    Iranmanesh, Seyed Mehdi
    Doretto, Gianfranco
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 30 (NIPS 2017), 2017, 30
  • [10] Rethinking Generalization in Few-Shot Classification
    Hiller, Markus
    Ma, Rongkai
    Harandi, Mehrtash
    Drummond, Tom
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,