Return
Enhancing multi-task performance through associative adversarial learning based on selective attacks
DOI:10.1016/j.neucom.2025.130229.png)
Abstract
En 中文
Adversarial learning can enhance model robustness against adversarial attacks. However, traditional adversarial learning generates adversarial samples by adding perturbations to entire images, causing excessive differences between adversarial samples and clean samples. To address this issue, we introduce the Associative Adversarial Learning (AAL) method based on a selective attack that can add perturbations to the images according to spatial attention maps, which demonstrate smaller differences from clean samples compared to those generated by global attacks. Thereby, it prevents the degradation of the model performance in clean samples. To further improve the robustness of the model, we develop a backtracking algorithm to effectively learn associative attention, enabling us to decouple attention from adversarial perturbations and mitigate the impact of adversarial attacks on the attention mechanism. Associative attention helps identify the key regions of adversarial examples, thereby enhancing the robustness of the models. We also introduce a projection function for associative attention, which allows AAL to select different attacking regions across various tasks, thus enabling its applicability to a variety of scenarios. Our experimental results show that AAL can be seamlessly integrated into various models, significantly improving adversarial robustness against multiple attacks. For example, AAL can increase InfraRed Small Target Detection mAP on SIRST-v2 by 4.5% and the accuracy of few-shot recognition on miniImageNet by 1.63%.
Keywords:
Adversarial learning
Selective attacks
Infrared small target detection
Journal
IF:
6.5
Papers:
2.5W
Citations:
6.5W
Organization
No organization information available

