arrow
返回

Minimizing Adversarial Training Samples for Robust Image Classifiers: Analysis and Adversarial Example Generator Design

delete2024-01-01
delete1
PRE
AI
Y
Yulong Wang *
T
Tong Sun
X
Xin Yuan
S
Shenghong Li
W
Wei Ni
DOI:10.1109/TIFS.2024.3474973delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Training deep neural networks (DNNs) with altered data, known as adversarial training, is essential for improving their robustness. A significant challenge emerges as the robustness strengthened during training often diminishes during inference, resulting in drops in robust pronounced accuracy. Contemporary strategies either necessitate excessively large training data or risk compromising the natural accuracy of non-adversarial images. Our analysis identifies that the inherent vulnerability of DNNs to adversarial attacks stems from certain input space segments that are inadequately populated by training data, leading to decision-making voids with incorrect predictions. The minimum number of training samples required for successful adversarial training can be attained by maximizing the representativeness of the samples. In light of this, we put forth an advanced training data augmentation method anchored on a Generative Adversarial Network. The generated samples are evaluated by the image classifier during training and selected based on their confidence scores. Evaluations on public datasets, such as Tiny-ImageNet, MS COCO, and CIFAR-100, using various deep neural networks (DNNs), including Vision Transformer, MobileNet, and WideResNet, under recent attacks like DifAttack, SQBA, and AutoAttack, confirm that our method significantly enhances the adversarial robustness of DNN image classifiers. Our method outperforms state-of-the-art adversarial training methods by 35.66% on Tiny-ImageNet, 13.53% on MS COCO, and 13.06% on CIFAR-100.
Keyword:
Deep neural network
adversarial training
generative adversarial network.

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

B
beijing university of posts & telecommunications
学者数:
1.4W
论文数: 1.2W
被引数: 9
C
引用论文

引用论文

The cyclobutane dimers of 5-methylcytosine and their deamination products
err2004-10-01
err0
errOAAI
errMartin D. Shetlar; Vladimir J. Basus; Arnold M. Falick; Anwer Mujeeb
err分享
err收藏
学者 查看更多内容