Frequency Regularization for Improving Adversarial Robustness

12/24/2022
by   Binxiao Huang, et al.
0

Deep neural networks are incredibly vulnerable to crafted, human-imperceptible adversarial perturbations. Although adversarial training (AT) has proven to be an effective defense approach, we find that the AT-trained models heavily rely on the input low-frequency content for judgment, accounting for the low standard accuracy. To close the large gap between the standard and robust accuracies during AT, we investigate the frequency difference between clean and adversarial inputs, and propose a frequency regularization (FR) to align the output difference in the spectral domain. Besides, we find Stochastic Weight Averaging (SWA), by smoothing the kernels over epochs, further improves the robustness. Among various defense schemes, our method achieves the strongest robustness against attacks by PGD-20, C&W and Autoattack, on a WideResNet trained on CIFAR-10 without any extra data.

READ FULL TEXT

page 2

page 3

research
06/25/2023

A Spectral Perspective towards Understanding and Improving Adversarial Robustness

Deep neural networks (DNNs) are incredibly vulnerable to crafted, imperc...
research
04/26/2021

Impact of Spatial Frequency Based Constraints on Adversarial Robustness

Adversarial examples mainly exploit changes to input pixels to which hum...
research
02/22/2019

On the Sensitivity of Adversarial Robustness to Input Data Distributions

Neural networks are vulnerable to small adversarial perturbations. Exist...
research
11/04/2022

Improving Adversarial Robustness to Sensitivity and Invariance Attacks with Deep Metric Learning

Intentionally crafted adversarial samples have effectively exploited wea...
research
07/19/2023

Towards Building More Robust Models with Frequency Bias

The vulnerability of deep neural networks to adversarial samples has bee...
research
07/07/2020

Robust Learning with Frequency Domain Regularization

Convolution neural networks have achieved remarkable performance in many...
research
06/10/2020

Deterministic Gaussian Averaged Neural Networks

We present a deterministic method to compute the Gaussian average of neu...

Please sign up or login with your details

Forgot password? Click here to reset