arrow
返回

Hyperspherical class prototypes for adversarial robustness

delete2022-05-01
delete9
PRE
AI
V
Vasileios Mygdalis *
I
Ioannis Pitas
DOI:10.1016/j.patcog.2022.108527delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
This work addresses the problem of adversarial robustness in deep neural network classification from an optimal class boundary estimation perspective. It is argued that increased model robustness to adversarial attacks can be achieved when the feature learning process is monitored by geometrically-inspired opti-mization criteria. To this end, we propose to learn hyperspherical class prototypes in the neural feature embedding space, along with training the network parameters. Three concurrent optimization functions for the intermediate hidden layer training data activations are devised, requiring items of the same class to be enclosed by the corresponding class prototype boundaries, to have minimum distance from their class prototype vector (i.e., hypersphere center) and to have maximum distance from the remainder hy-persphere centers. Our experiments show that training standard classification model architectures with the proposed objectives, significantly increases their robustness to white-box adversarial attacks, without adverse (if not beneficial) effects to their classification accuracy. (c) 2022 Elsevier Ltd. All rights reserved.
Keyword:
Adversarial defense
Adversarial robustness
Hypersphere prototype loss
HCP loss

期刊

Pattern Recognition 封面图
Pattern Recognition
IF:
7.6
论文数:
1.3W
被引数:
4.5W

机构

A
aristotle university of thessaloniki
学者数:
2.6W
论文数: 2.0W
被引数: 19
引用论文

引用论文

Effect of oxygen availability and pH on the furan concentration formed during thermal preservation of plant-based foods
err2016-03-04
err0
errOAAI
errStijn Palmers; Tara Grauwet; Laura Vanden Avenne; Thomas Verhaeghe; Biniam T. Kebede; Marc E. Hendrickx; Ann Van Loey
err分享
err收藏
Graph Embedded One-Class Classifiers for media data classification
err2016-12-01
err36
errOAAI
errMygdalis, Vasileios; Iosifidis, Alexandros; Tefas, Anastasios; Pitas, Ioannis
err分享
err收藏
err分享
err收藏
K-Anonymity inspired adversarial attack and multiple one-class classification defense
err2020-04-01
err12
PREAI
errMygdalis, Vasileios; Tefas, Anastasios; Pitas, Ioannis
err分享
err收藏
Surrogate network-based sparseness hyper-parameter optimization for deep expression recognition
err2021-03-01
err17
PREAI
errXie, Weicheng; Chen, Wenting; Shen, Linlin; Duan, Jinming; Yang, Meng
err分享
err收藏
Semi-supervised subclass support vector data description for image and video classification
err2018-02-01
err24
PREAI
errMygdalis, Vasileios; Iosifidis, Alexandros; Tefas, Anastasios; Pitas, Ioannis
err分享
err收藏
Cost-conscious comparison of supervised learning algorithms over multiple data sets
err2012-04-01
err35
PREAI
errUlas, Aydin; Yildiz, Olcay Taner; Alpaydin, Ethem
err分享
err收藏
err分享
err收藏
Cell Preparation and Multicolor FISH in 3D Preserved Cultured Mammalian Cells
err2010-12-02
err0
PREAI
errMarion Cremer; Stefan Müller; Daniela Köhler; Alessandro Brero; Irina Solovei
err分享
err收藏
Adversarial Attacks and Defenses in Deep Learning深度学习中的对抗性攻击和防御
err2020-03-01
err354
errOAAI
errRen, Kui; Zheng, Tianhang; Qin, Zhan; Liu, Xue
err分享
err收藏
学者 查看更多内容