Enhancing Generalization in Few-Shot Learning for Detecting Unknown Adversarial Examples

被引:0
|
作者
Liu, Wenzhao [1 ,2 ]
Zhang, Wanli [1 ]
Yang, Kuiwu [1 ]
Chen, Yue [1 ]
Guo, Kaiwei [1 ]
Wei, Jianghong [1 ]
机构
[1] State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Henan, Peoples R China
[2] Natl Univ Def Technol, Environm Effects Elect & Informat Syst, State key Lab Complex Electromagnet, Changsha 471000, Hunan, Peoples R China
基金
中国国家自然科学基金; 中国博士后科学基金;
关键词
Adversarial example detection; Few-shot learning; Prototypical network; New adversarial attacks; ATTACKS; VISION;
D O I
10.1007/s11063-024-11572-6
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks, particularly convolutional neural networks, are vulnerable to adversarial examples, undermining their reliability in visual recognition tasks. Adversarial example detection is a crucial defense mechanism against such attacks but often relies on empirical observations and specialized metrics, posing challenges in terms of data efficiency, generalization to unknown attacks, and scalability to high-resolution datasets like ImageNet. To address these issues, we propose a prototypical network-based method using a deep residual network as the backbone architecture. This approach is capable of extracting discriminative features of adversarial and normal examples from various known adversarial examples by constructing few-shot adversarial detection tasks. Then the optimal mapping matrix is computed using the Sinkhorn algorithm from optimal transport theory, and the class centers are iteratively updated, enabling the detection of unknown adversarial examples across scenarios. Experimental results show that the proposed approach outperforms existing methods in the cross-adversary benchmark and achieves enhanced generalization on a subset of ImageNet in detecting both new adversarial attacks and adaptive white-box attacks. The proposed approach offers a promising solution for improving the safety of deep neural networks in practical applications.
引用
收藏
页数:25
相关论文
共 50 条
  • [41] Interpretable Compositional Representations for Robust Few-Shot Generalization
    Mishra, Samarth
    Zhu, Pengkai
    Saligrama, Venkatesh
    [J]. IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2024, 46 (03) : 1496 - 1512
  • [42] Few-shot classification guided by generalization error bound
    Liu, Fan
    Yang, Sai
    Chen, Delong
    Huang, Huaxi
    Zhou, Jun
    [J]. PATTERN RECOGNITION, 2024, 145
  • [43] Co-Learning for Few-Shot Learning
    Xu, Rui
    Xing, Lei
    Shao, Shuai
    Liu, Baodi
    Zhang, Kai
    Liu, Weifeng
    [J]. NEURAL PROCESSING LETTERS, 2022, 54 (04) : 3339 - 3356
  • [44] Learning about few-shot concept learning
    Ananya Rastogi
    [J]. Nature Computational Science, 2022, 2 : 698 - 698
  • [45] Co-Learning for Few-Shot Learning
    Rui Xu
    Lei Xing
    Shuai Shao
    Baodi Liu
    Kai Zhang
    Weifeng Liu
    [J]. Neural Processing Letters, 2022, 54 : 3339 - 3356
  • [46] RankDNN: Learning to Rank for Few-Shot Learning
    Guo, Qianyu
    Gong Haotong
    Wei, Xujun
    Fu, Yanwei
    Yu, Yizhou
    Zhang, Wenqiang
    Ge, Weifeng
    [J]. THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 1, 2023, : 728 - 736
  • [47] Few-shot Learning with Prompting Methods
    [J]. 2023 6TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION AND IMAGE ANALYSIS, IPRIA, 2023,
  • [48] Active Few-Shot Learning with FASL
    Muller, Thomas
    Perez-Torro, Guillermo
    Basile, Angelo
    Franco-Salvador, Marc
    [J]. NATURAL LANGUAGE PROCESSING AND INFORMATION SYSTEMS (NLDB 2022), 2022, 13286 : 98 - 110
  • [49] Prototype Completion for Few-Shot Learning
    Zhang, Baoquan
    Li, Xutao
    Ye, Yunming
    Feng, Shanshan
    [J]. IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (10) : 12250 - 12268
  • [50] Few-Shot Learning With a Strong Teacher
    Ye, Han-Jia
    Ming, Lu
    Zhan, De-Chuan
    Chao, Wei-Lun
    [J]. IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2024, 46 (03) : 1425 - 1440