arrow
Return

Image Representation Induced Subspaces for Practical Classification Robustness

delete2026-01-12
delete0
PRE
AI
M
Mohamed-Hicham Leghettas
M
Markus Püschel
DOI:10.1109/TIP.2025.3650023delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Both classical and learned image transformations such as the discrete wavelet transforms (DWTs) and flow-based generative models provide semantically meaningful representations of images. In this paper, we exploit the expressiveness of these representations to propose a general method for improving the classification robustness of neural network against real-world corruptions. The key idea is a novel adversarial attack that targets suitable low-dimensional subspaces in the transformed space while at the same time obeying the $L^{\infty } $ -box in the pixel space. Subsequent training for adversarial robustness with this attack is then used as a proxy for achieving corruption robustness. We apply this approach with the discrete cosine transform (DCT), DWTs, and Glow with attacks that preserve low frequencies or the most relevant features, respectively. The resulting models are significantly more robust against a broad class of unseen common image perturbations compared to using the standard $L^{\infty } $ -box, with only a minor sacrifice of natural accuracy. We provide an extensive ablation study, which shows that our method applies quite generally for two different color systems and choice of relevant parameters and also provides insight into why our method works.
Keywords:
Adversarial machine learning
corruption robustness
adversarial training
invertible image representations

Journal

IEEE Transactions on Image Processing cover
IEEE Transactions on Image Processing
IF:
13.7
Papers:
1.0W
Citations:
8.4W

Organization

E
ETH Zurich
Scholars:
3.0W
Papers: 2.4W
Citations: 8.4W
Cited Papers

Cited Papers

Cartoon Explanations of Image Classifiers
err2022-10-23
err0
PREAI
errStefan Kolek; Duc Anh Nguyen; Ron Levie; Joan Bruna; Gitta Kutyniok
errShare
errSave
Efficient Robust Training via Backward Smoothing
err2022-06-28
err0
errOAAI
errJinghui Chen; Yu Cheng; Zhe Gan; Quanquan Gu; Jingjing Liu
errShare
errSave
Universal screen-shooting robust image watermarking with channel-attention in DCT domain
err2024-03-01
err11
PREAI
errCao, Fang; Guo, Daidou; Wang, Tianjun; Yao, Heng; Li, Jian; Qin, Chuan
errShare
errSave
err
IF0
err
err0
errOAAI
err
errShare
errSave
The Limitations of Deep Learning in Adversarial Settings
err2016-03-01
err0
errOAAI
errNicolas Papernot; Patrick McDaniel; Somesh Jha; Matt Fredrikson; Z. Berkay Celik; Ananthram Swami
errShare
errSave
errShare
errSave
researcher View more