arrow
Return

Improving robustness with image filtering

delete2024-09-01
delete0
delete
OA
AI
M
Matteo Terzi
M
Mattia Carletti *
G
Gian Antonio Susto
DOI:10.1016/j.neucom.2024.127927delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Adversarial robustness is one of the most challenging problems in Deep Learning and Computer Vision research. State-of-the-art techniques to enforce robustness are based on Adversarial Training, a computationally costly optimization procedure. For this reason, many alternative solutions have been proposed, but none proved effective under stronger or adaptive attacks. This paper presents Image-Graph Extractor (IGE), a new image filtering scheme that extracts the fundamental nodes of an image and their connections through a graph structure. By utilizing the IGE representation, we have developed a new defense technique, Filtering as a Defense, which prevents attackers from creating malicious patterns that can deceive image classifiers. Moreover, we show that data augmentation with filtered images effectively improves the model's robustness to data corruptions. We validate our techniques on Convolutional Neural Networks on CIFAR-10, CIFAR-100, and ImageNet.
Keywords:
Robustness
Adversarial attacks and defenses
Adversarial training
Deep Neural Networks
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Neurocomputing cover
Neurocomputing
IF:
6.5
Papers:
2.5W
Citations:
6.5W

Organization

U
University of Padua
Scholars:
5.1W
Papers: 4.3W
Citations: 57