arrow
返回

Semantically Consistent Visual Representation for Adversarial Robustness

delete2023-01-01
delete2
PRE
AI
H
Huafeng Kuang
H
Hong Liu
Y
Yongjian Wu
R
Rongrong Ji *
DOI:10.1109/TIFS.2023.3306933delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Deep neural networks have been widely used in various domains owing to the success of deep learning. However, recent studies have shown that these models are vulnerable to adversarial examples, leading to inaccurate predictions. In this paper, we focus on the issue of adversarial robustness by examining it through the lens of semantic information, which drives us to propose a new perspective, i.e., adversarial attacks destroy the correlation between visual representations and semantic word vectors, while adversarial training restores it. Additionally, we discover that the correlation among robust representations of different categories aligns with the correlation among the corresponding semantic word vectors. Based on these empirical observations, we incorporate the semantic information into the model training process and propose Semantic Constraint Adversarial Robust Learning (SCARL). Firstly, inspired by the information-theoretical perspective, we maximize mutual information to bridge the information gap between the visual representations and the corresponding semantic word vectors in the embedding space. We further provide a differentiable lower bound to optimize such mutual information efficiently. Secondly, we introduce a novel semantic structure constraint that maintains the structure of visual representations consistent with that of semantic word vectors. Finally, we integrate these techniques with adversarial training to learn robust visual representations. We conduct extensive experiments on several datasets (such as CIFAR and TinyImageNet) and evaluate the robustness against various adversarial attacks (such as PGD-attack and AutoAttack), demonstrating the benefits of incorporating semantic information for improving model robustness.
Keyword:
Semantics
Visualization
Robustness
Training
Correlation
Task analysis
Representation learning
Adversarial robustness
adversarial training
word embeddings
semantic information

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.2K
被引数:
2.3W

机构

N
national institute of informatics (nii) - japan
学者数:
453
论文数: 420
被引数: 0
R
research organization of information & systems (rois)
学者数:
2.8K
论文数: 3.2K
被引数: 2
X
xiamen university
学者数:
5.9W
论文数: 3.8W
被引数: 67
学者 查看更多机构
引用论文

引用论文

err2001-01-01
err0
PREAI
errSergei Scherbov; Harrie van Vianen
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
学者 查看更多内容