Improving Resistance to Adversarial Deformations by Regularizing Gradients

08/29/2020
by   Pengfei Xia, et al.
0

Improving the resistance of deep neural networks against adversarial attacks is important for deploying models to realistic applications. Currently, most defense methods are designed to defend against additive noise attacks, their performance cannot be guaranteed when against non-additive noise attacks. In this paper, we focus on adversarial deformations, a typical class of non-additive noise attacks, and propose a flow gradient regularization with random start to improve the resistance of models. Theoretically, we prove that, compared with input gradient regularization, regularizing flow gradients is able to get a tighter bound. Across multiple datasets, architectures, and adversarial deformations, our experimental results consistently indicate that models trained with flow gradient regularization can acquire a better resistance than trained with input gradient regularization with a large margin. Moreover, compared with adversarial training, our method can achieve better results in optimization-based and gradient-free attacks, and combining these two methods can improve the resistance against deformation attacks further. Finally, we give a unified form of gradient regularization, which can be used to derive the corresponding form when facing other types of attack.

READ FULL TEXT
research
11/04/2022

Adversarial Defense via Neural Oscillation inspired Gradient Masking

Spiking neural networks (SNNs) attract great attention due to their low ...
research
05/27/2019

Scaleable input gradient regularization for adversarial robustness

Input gradient regularization is not thought to be an effective means fo...
research
02/02/2022

An Eye for an Eye: Defending against Gradient-based Attacks with Gradients

Deep learning models have been shown to be vulnerable to adversarial att...
research
03/14/2022

Defending Against Adversarial Attack in ECG Classification with Adversarial Distillation Training

In clinics, doctors rely on electrocardiograms (ECGs) to assess severe c...
research
09/17/2020

MultAV: Multiplicative Adversarial Videos

The majority of adversarial machine learning research focuses on additiv...
research
01/26/2020

Ensemble Noise Simulation to Handle Uncertainty about Gradient-based Adversarial Attacks

Gradient-based adversarial attacks on neural networks can be crafted in ...
research
09/19/2019

Absum: Simple Regularization Method for Reducing Structural Sensitivity of Convolutional Neural Networks

We propose Absum, which is a regularization method for improving adversa...

Please sign up or login with your details

Forgot password? Click here to reset