返回
Image Representation Induced Subspaces for Practical Classification Robustness
DOI:10.1109/TIP.2025.3650023.png)
摘要
En 中文
Both classical and learned image transformations such as the discrete wavelet transforms (DWTs) and flow-based generative models provide semantically meaningful representations of images. In this paper, we exploit the expressiveness of these representations to propose a general method for improving the classification robustness of neural network against real-world corruptions. The key idea is a novel adversarial attack that targets suitable low-dimensional subspaces in the transformed space while at the same time obeying the $L^{\infty } $ -box in the pixel space. Subsequent training for adversarial robustness with this attack is then used as a proxy for achieving corruption robustness. We apply this approach with the discrete cosine transform (DCT), DWTs, and Glow with attacks that preserve low frequencies or the most relevant features, respectively. The resulting models are significantly more robust against a broad class of unseen common image perturbations compared to using the standard $L^{\infty } $ -box, with only a minor sacrifice of natural accuracy. We provide an extensive ablation study, which shows that our method applies quite generally for two different color systems and choice of relevant parameters and also provides insight into why our method works.
Keyword:
Adversarial machine learning
corruption robustness
adversarial training
invertible image representations
期刊
IF:
13.7
论文数:
1.0W
被引数:
8.4W
机构
引用论文
Defense Against Adversarial Attacks with Efficient Frequency-Adaptive Compression and Reconstruction
PATTERN RECOGNITION
IF7.6

