Robust feature learning for adversarial defense via hierarchical feature alignment

被引:59
|
作者
Zhang, Xiaoqin [1 ]
Wang, Jinxin [1 ]
Wang, Tao [1 ]
Jiang, Runhua [1 ]
Xu, Jiawei [1 ]
Zhao, Li [1 ]
机构
[1] Wenzhou Univ, Coll Comp Sci & Artificial Intelligence, Wenzhou 325035, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial defense; Domain adaptation; Feature alignment; Optimal transport;
D O I
10.1016/j.ins.2020.12.042
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep neural networks have demonstrated excellent performance in most computer vision tasks in recent years. However, they are vulnerable to adversarial perturbations generated by adversarial attacks. These human-imperceptible perturbations often lead to severe distortion in the high-dimensional intermediate feature space, which is one of the major reasons for the vulnerabilities in deep neural networks. Therefore, input images with perturbations can completely change the predictions of the networks in the decision space. To overcome this drawback, we propose to progressively align the intermediate feature representations extracted from the adversarial domain with feature representations extracted from a clean domain through domain adaptation. The difference between two feature distributions can be accurately measured via an optimal transport-based Wasserstein distance. Thus, the deep networks are forced to learn robust and domain-invariant feature representations, so that the gap between the different domains is minimized and that the networks are no longer easily fooled by diverse adversaries. Extensive evaluations are conducted on four classification benchmark datasets in white-box attack scenarios. The evaluation results demonstrate a significant performance improvement over several state-of-the-art defense methods. (C) 2020 Elsevier Inc. All rights reserved.
引用
收藏
页码:256 / 270
页数:15
相关论文
共 50 条
  • [21] Robust dimensionality reduction via feature space to feature space distance metric learning
    Li, Bo
    Fan, Zhang-Tao
    Zhang, Xiao-Long
    Huang, De-Shuang
    NEURAL NETWORKS, 2019, 112 : 1 - 14
  • [22] Robust Feature Selection with Feature Correlation via Sparse Multi-Label Learning
    Cheng, Jiangjiang
    Mei, Junmei
    Zhong, Jing
    Men, Min
    Zhong, Ping
    PATTERN RECOGNITION AND IMAGE ANALYSIS, 2020, 30 (01) : 52 - 62
  • [23] Structure-Coherent Deep Feature Learning for Robust Face Alignment
    Lin, Chunze
    Zhu, Beier
    Wang, Quan
    Liao, Renjie
    Qian, Chen
    Lu, Jiwen
    Zhou, Jie
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2021, 30 (30) : 5313 - 5326
  • [24] Robust Feature Selection with Feature Correlation via Sparse Multi-Label Learning
    Jiangjiang Cheng
    Junmei Mei
    Jing Zhong
    Min Men
    Ping Zhong
    Pattern Recognition and Image Analysis, 2020, 30 : 52 - 62
  • [25] GAMnet: Robust Feature Matching via Graph Adversarial-Matching Network
    Jiang, Bo
    Sun, Pengfei
    Zhang, Ziyan
    Tang, Jin
    Luo, Bin
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 5419 - 5426
  • [26] Robust Regression via Online Feature Selection under Adversarial Data Corruption
    Zhang, Xuchao
    Lei, Shuo
    Zhao, Liang
    Boedihardjo, Arnold P.
    Lu, Chang-Tien
    2018 IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2018, : 1440 - 1445
  • [27] A Robust Adaptive Hierarchical Learning Crow Search Algorithm for Feature Selection
    Chen, Yilin
    Ye, Zhi
    Gao, Bo
    Wu, Yiqi
    Yan, Xiaohu
    Liao, Xiangyun
    ELECTRONICS, 2023, 12 (14)
  • [28] Domain Generalization with Adversarial Feature Learning
    Li, Haoliang
    Pan, Sinno Jialin
    Wang, Shiqi
    Kot, Alex C.
    2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2018, : 5400 - 5409
  • [29] Sparse Feature Attacks in Adversarial Learning
    Yin, Zhizhou
    Wang, Fei
    Liu, Wei
    Chawla, Sanjay
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2018, 30 (06) : 1164 - 1177
  • [30] Face hallucination via multiple feature learning with hierarchical structure
    Liu, Licheng
    Liu, Han
    Li, Shutao
    Chen, C. L. Philip
    INFORMATION SCIENCES, 2020, 512 (512) : 416 - 430