arrow
返回

Improving Adversarial Robustness Against Universal Patch Attacks Through Feature Norm Suppressing

delete2025-01-01
delete1
PRE
AI
C
Cheng Yu
J
Jiansheng Chen *
Y
Yu Wang
Y
Youze Xue
马
马惠敏 (Huimin Ma)
DOI:10.1109/TNNLS.2023.3326871delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Universal adversarial patch attacks, which are readily implemented, have been validated to be able to fool real-world deep convolutional neural networks (CNNs), posing a serious threat to practical computer vision systems based on CNNs. Unfortunately, current defending approaches are severely understudied facing the following problems. Patch detection-based methods suffer from dramatic performance drops against white-box or adaptive attacks since they rely heavily on empirical clues. Methods based on adversarial training or certified defense are difficult to be scaled up to large-scale datasets or complex practical networks due to prohibitively high computational overhead or over strong assumptions on the network structure. In this article, we focus on two cases of widely adopted universal adversarial patch attacks, namely the universal targeted attack on image classifiers and the universal vanishing attack on object detectors. We find that, for popular CNNs, the attacking success of the adversarial patch relies on feature vectors centered at the patch location with large norm in classifiers and large channel-aware norm (CA-Norm) in detectors, and further present a mathematical explanation for this phenomenon. Based on this, we propose a simple but effective defending method using the feature norm suppressing (FNS) layer, which can renormalize the feature norm by nonincreasing functions. As a differentiable module, FNS can be adaptively inserted in various CNN architectures to achieve multistage suppression of the generation of large norm feature vectors. Moreover, FNS is efficient with no trainable parameters and very low computational overhead. We evaluate our proposed defending method across multiple CNN architectures and datasets against the strong adaptive white-box attacks in both visual classification and detection tasks. In both tasks, FNS significantly outperforms previous defending methods on adversarial robustness with a relatively low influence on the performance of benign images. Code is available at https://github.com/jschenthu/FNS.
Keyword:
Channel-aware norm (CA-Norm)
feature norm suppressing (FNS)
image classification
object detection
universal adversarial patch

期刊

IEEE Transactions on Neural Networks and Learning Systems 封面图
IEEE Transactions on Neural Networks and Learning Systems
IF:
8.9
论文数:
7.6K
被引数:
7.2W

机构

T
tsinghua university
学者数:
11.9W
论文数: 10.0W
被引数: 137
引用论文

引用论文

Blastococcus capsensis sp. nov., isolated from an archaeological Roman pool and emended description of the genus Blastococcus, B. aggregatus, B. saxobsidens, B. jejuensis and B. endophyticus
err2016-11-01
err0
errOAAI
errKarima Hezbri; Moussa Louati; Imen Nouioui; Maher Gtari; Manfred Rohde; Cathrin Spröer; Peter Schumann; Hans-Peter Klenk; Faten Ghodhbane-Gtari; Maria del Carmen Montero-Calasanz
err分享
err收藏
err分享
err收藏
Denoising Adversarial Autoencoders
err2019-04-01
err93
errOAAI
errCreswell, Antonia; Bharath, Anil Anthony
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容