返回
Towards Robust Semantic Segmentation against Patch-Based Attack via Attention Refinement
DOI:10.1007/s11263-024-02120-9.png)
摘要
En 中文
The attention mechanism has been proven effective on various visual tasks in recent years. In the semantic segmentation task, the attention mechanism is applied in various methods, including the case of both convolution neural networks and vision transformer as backbones. However, we observe that the attention mechanism is vulnerable to patch-based adversarial attacks. Through the analysis of the effective receptive field, we attribute it to the fact that the wide receptive field brought by global attention may lead to the spread of the adversarial patch. To address this issue, in this paper, we propose a robust attention mechanism (RAM) to improve the robustness of the semantic segmentation model, which can notably relieve the vulnerability against patch-based attacks. Compared to the vallina attention mechanism, RAM introduces two novel modules called max attention suppression and random attention dropout, both of which aim to refine the attention matrix and limit the influence of a single adversarial patch on the semantic segmentation results of other positions. Extensive experiments demonstrate the effectiveness of our RAM to improve the robustness of semantic segmentation models against various patch-based attack methods under different attack settings.
Keyword:
Model robustness
Attention mechanism
Semantic segmentation
Patch-based attack
期刊
IF:
9.3
论文数:
3.9K
被引数:
2.8W
机构
引用论文
Inflexibility of mental planning: A characteristic disorder with prefrontal lobe lesions?心理计划的僵化: 前额叶病变的特征性障碍?
In vitro and in vivo binding of neuroactive steroids to the sigma‐1 receptor as measured with the positron emission tomography radioligand [18F]FPS
Synapse
IF0
SegViT v2: Exploring Efficient and Continual Semantic Segmentation with Plain Vision TransformersSegViT v2: 使用普通视觉转换器探索高效和连续的语义分割
Recent Development of Dual-Dictionary Learning Approach in Medical Image Analysis and Reconstruction

