Robust feature learning for adversarial defense via hierarchical feature alignment

被引:59
|
作者
Zhang, Xiaoqin [1 ]
Wang, Jinxin [1 ]
Wang, Tao [1 ]
Jiang, Runhua [1 ]
Xu, Jiawei [1 ]
Zhao, Li [1 ]
机构
[1] Wenzhou Univ, Coll Comp Sci & Artificial Intelligence, Wenzhou 325035, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial defense; Domain adaptation; Feature alignment; Optimal transport;
D O I
10.1016/j.ins.2020.12.042
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep neural networks have demonstrated excellent performance in most computer vision tasks in recent years. However, they are vulnerable to adversarial perturbations generated by adversarial attacks. These human-imperceptible perturbations often lead to severe distortion in the high-dimensional intermediate feature space, which is one of the major reasons for the vulnerabilities in deep neural networks. Therefore, input images with perturbations can completely change the predictions of the networks in the decision space. To overcome this drawback, we propose to progressively align the intermediate feature representations extracted from the adversarial domain with feature representations extracted from a clean domain through domain adaptation. The difference between two feature distributions can be accurately measured via an optimal transport-based Wasserstein distance. Thus, the deep networks are forced to learn robust and domain-invariant feature representations, so that the gap between the different domains is minimized and that the networks are no longer easily fooled by diverse adversaries. Extensive evaluations are conducted on four classification benchmark datasets in white-box attack scenarios. The evaluation results demonstrate a significant performance improvement over several state-of-the-art defense methods. (C) 2020 Elsevier Inc. All rights reserved.
引用
收藏
页码:256 / 270
页数:15
相关论文
共 50 条
  • [1] UNMASK: Adversarial Detection and Defense Through Robust Feature Alignment
    Freitas, Scott
    Chen, Shang-Tse
    Wang, Zijie J.
    Chau, Duen Horng
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 1081 - 1088
  • [2] Boosting adversarial robustness via feature refinement, suppression, and alignment
    Wu, Yulun
    Guo, Yanming
    Chen, Dongmei
    Yu, Tianyuan
    Xiao, Huaxin
    Guo, Yuanhao
    Bai, Liang
    COMPLEX & INTELLIGENT SYSTEMS, 2024, 10 (03) : 3213 - 3233
  • [3] Boosting adversarial robustness via feature refinement, suppression, and alignment
    Yulun Wu
    Yanming Guo
    Dongmei Chen
    Tianyuan Yu
    Huaxin Xiao
    Yuanhao Guo
    Liang Bai
    Complex & Intelligent Systems, 2024, 10 : 3213 - 3233
  • [4] Adversarial feature distribution alignment for semi-supervised learning
    Mayer, Christoph
    Paul, Matthieu
    Timofte, Radu
    COMPUTER VISION AND IMAGE UNDERSTANDING, 2021, 202
  • [5] Hierarchical Image Feature Compression for Machines via Feature Sparsity Learning
    Ding, Ding
    Chen, Zhenzhong
    Liu, Zizheng
    Xu, Xiaozhong
    Liu, Shan
    IEEE SIGNAL PROCESSING LETTERS, 2024, 31 : 1159 - 1163
  • [6] Adaptive feature alignment for adversarial training
    Zhao, Kai
    Wang, Tao
    Zhang, Ruixin
    Shen, Wei
    PATTERN RECOGNITION LETTERS, 2024, 186 : 184 - 190
  • [7] Adversarial Domain Generalization Defense via Task-Relevant Feature Alignment in Cyber-Physical Systems
    Zhang, Sicheng
    Liu, Jie
    Bao, Zhida
    Yang, Yandie
    Wang, Meiyu
    Lin, Yun
    IEEE TRANSACTIONS ON RELIABILITY, 2024, : 1 - 14
  • [8] Learning Invariant Representation Via Contrastive Feature Alignment for Clutter Robust SAR ATR
    Peng B.
    Xie J.
    Peng B.
    Liu L.
    IEEE Geoscience and Remote Sensing Letters, 2023, 20
  • [9] Hierarchical Feature Alignment for Transfer Learning on Neural Decoding Tasks
    Eryol, Erkin
    Vural, Fatos T. Yarman
    2022 IEEE 22ND INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOENGINEERING (BIBE 2022), 2022, : 249 - 254
  • [10] Boosting transferability of targeted adversarial examples with non-robust feature alignment
    Zhu, Hegui
    Sui, Xiaoyan
    Ren, Yuchen
    Jia, Yanmeng
    Zhang, Libo
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 227