Enhancing Intrinsic Adversarial Robustness via Feature Pyramid Decoder

被引:9
|
作者
Li, Guanlin [1 ]
Ding, Shuya [2 ]
Luo, Jun [2 ]
Liu, Chang [2 ]
机构
[1] Natl Supercomp Ctr Jinan, Shandong Prov Key Lab Comp Networks, Shandong Comp Sci Ctr, Jinan, Peoples R China
[2] Nanyang Technol Univ, Sch Comp Sci & Engn, Singapore, Singapore
关键词
D O I
10.1109/CVPR42600.2020.00088
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Whereas adversarial training is employed as the main defence strategy against specific adversarial samples, it has limited generalization capability and incurs excessive time complexity. In this paper, we propose an attack-agnostic defence framework to enhance the intrinsic robustness of neural networks, without jeopardizing the ability of generalizing clean samples. Our Feature Pyramid Decoder (FPD) framework applies to all block-based convolutional neural networks (CNNs). It implants denoising and image restoration modules into a targeted CNN, and it also constraints the Lipschitz constant of the classification layer. Moreover, we propose a two-phase strategy to train the FPD-enhanced CNN, utilizing c-neighbourhood noisy images with multi-task and self-supervised learning. Evaluated against a variety of white-box and black-box attacks, we demonstrate that FPD-enhanced CNNs gain sufficient robustness against general adversarial samples on MNIST, SVHN and CALTECH. In addition, if we further conduct adversarial training, the FPD-enhanced CNNs perform better than their non-enhanced versions.
引用
收藏
页码:797 / 805
页数:9
相关论文
共 50 条
  • [1] Towards Adversarial Robustness via Feature Matching
    Li, Zhuorong
    Feng, Chao
    Zheng, Jianwei
    Wu, Minghui
    Yu, Hongchuan
    [J]. IEEE ACCESS, 2020, 8 (08): : 88594 - 88603
  • [2] Enhancing Adversarial Robustness via Anomaly-aware Adversarial Training
    Tang, Keke
    Lou, Tianrui
    He, Xu
    Shi, Yawen
    Zhu, Peican
    Gu, Zhaoquan
    [J]. KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT I, KSEM 2023, 2023, 14117 : 328 - 342
  • [3] Enhancing Adversarial Robustness via Stochastic Robust Framework
    Sun, Zhenjiang
    Li, Yuanbo
    Hu, Cong
    [J]. PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT IV, 2024, 14428 : 187 - 198
  • [4] TOWARDS ADVERSARIAL ROBUSTNESS VIA COMPACT FEATURE REPRESENTATIONS
    Shah, Muhammad A.
    Olivier, Raphael
    Raj, Bhiksha
    [J]. 2021 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP 2021), 2021, : 3845 - 3849
  • [5] Diversity supporting robustness: Enhancing adversarial robustness via differentiated ensemble predictions
    Chen, Xi
    Huang, Wei
    Peng, Ziwen
    Guo, Wei
    Zhang, Fan
    [J]. COMPUTERS & SECURITY, 2024, 142
  • [6] Enhancing Adversarial Robustness via Score-Based Optimization
    Zhang, Boya
    Luo, Weijian
    Zhang, Zhihua
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [7] Boosting adversarial robustness via feature refinement, suppression, and alignment
    Yulun Wu
    Yanming Guo
    Dongmei Chen
    Tianyuan Yu
    Huaxin Xiao
    Yuanhao Guo
    Liang Bai
    [J]. Complex & Intelligent Systems, 2024, 10 : 3213 - 3233
  • [8] Boosting adversarial robustness via feature refinement, suppression, and alignment
    Wu, Yulun
    Guo, Yanming
    Chen, Dongmei
    Yu, Tianyuan
    Xiao, Huaxin
    Guo, Yuanhao
    Bai, Liang
    [J]. COMPLEX & INTELLIGENT SYSTEMS, 2024, 10 (03) : 3213 - 3233
  • [9] Encoding Robustness to Image Style via Adversarial Feature Perturbations
    Shu, Manli
    Wu, Zuxuan
    Goldblum, Micah
    Goldstein, Tom
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [10] Enhancing Model Robustness and Accuracy Against Adversarial Attacks via Adversarial Input Training
    Ingle, Ganesh
    Pawale, Sanjesh
    [J]. International Journal of Advanced Computer Science and Applications, 2024, 15 (03) : 1210 - 1228