arrow
返回

Image Representation Induced Subspaces for Practical Classification Robustness

delete2026-01-12
delete0
PRE
AI
M
Mohamed-Hicham Leghettas
M
Markus Püschel
DOI:10.1109/TIP.2025.3650023delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Both classical and learned image transformations such as the discrete wavelet transforms (DWTs) and flow-based generative models provide semantically meaningful representations of images. In this paper, we exploit the expressiveness of these representations to propose a general method for improving the classification robustness of neural network against real-world corruptions. The key idea is a novel adversarial attack that targets suitable low-dimensional subspaces in the transformed space while at the same time obeying the $L^{\infty } $ -box in the pixel space. Subsequent training for adversarial robustness with this attack is then used as a proxy for achieving corruption robustness. We apply this approach with the discrete cosine transform (DCT), DWTs, and Glow with attacks that preserve low frequencies or the most relevant features, respectively. The resulting models are significantly more robust against a broad class of unseen common image perturbations compared to using the standard $L^{\infty } $ -box, with only a minor sacrifice of natural accuracy. We provide an extensive ablation study, which shows that our method applies quite generally for two different color systems and choice of relevant parameters and also provides insight into why our method works.
Keyword:
Adversarial machine learning
corruption robustness
adversarial training
invertible image representations

期刊

IEEE Transactions on Image Processing 封面图
IEEE Transactions on Image Processing
IF:
13.7
论文数:
1.0W
被引数:
8.4W

机构

E
ETH Zurich
学者数:
3.0W
论文数: 2.4W
被引数: 8.4W
引用论文

引用论文

Cartoon Explanations of Image Classifiers图像分类器的卡通图解释
err2022-10-23
err0
PREAI
errStefan Kolek; Duc Anh Nguyen; Ron Levie; Joan Bruna; Gitta Kutyniok
err分享
err收藏
Efficient Robust Training via Backward Smoothing
err2022-06-28
err0
errOAAI
errJinghui Chen; Yu Cheng; Zhe Gan; Quanquan Gu; Jingjing Liu
err分享
err收藏
Universal screen-shooting robust image watermarking with channel-attention in DCT domain
err2024-03-01
err11
PREAI
errCao, Fang; Guo, Daidou; Wang, Tianjun; Yao, Heng; Li, Jian; Qin, Chuan
err分享
err收藏
err
IF0
err
err0
errOAAI
err
err分享
err收藏
The Limitations of Deep Learning in Adversarial Settings
err2016-03-01
err0
errOAAI
errNicolas Papernot; Patrick McDaniel; Somesh Jha; Matt Fredrikson; Z. Berkay Celik; Ananthram Swami
err分享
err收藏
err分享
err收藏
学者 查看更多内容