Improving Robustness with Image Filtering

12/21/2021
by   Matteo Terzi, et al.
8

Adversarial robustness is one of the most challenging problems in Deep Learning and Computer Vision research. All the state-of-the-art techniques require a time-consuming procedure that creates cleverly perturbed images. Due to its cost, many solutions have been proposed to avoid Adversarial Training. However, all these attempts proved ineffective as the attacker manages to exploit spurious correlations among pixels to trigger brittle features implicitly learned by the model. This paper first introduces a new image filtering scheme called Image-Graph Extractor (IGE) that extracts the fundamental nodes of an image and their connections through a graph structure. By leveraging the IGE representation, we build a new defense method, Filtering As a Defense, that does not allow the attacker to entangle pixels to create malicious patterns. Moreover, we show that data augmentation with filtered images effectively improves the model's robustness to data corruption. We validate our techniques on CIFAR-10, CIFAR-100, and ImageNet.

READ FULL TEXT

page 1

page 5

page 6

page 7

page 12

page 13

page 14

research
03/26/2021

Adversarial Attacks are Reversible with Natural Supervision

We find that images contain intrinsic structure that enables the reversa...
research
08/20/2021

PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image Classifier

The adversarial patch attack against image classification models aims to...
research
05/28/2019

ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation

Deep neural networks are vulnerable to adversarial attacks. The literatu...
research
06/27/2023

Adversarial Training for Graph Neural Networks

Despite its success in the image domain, adversarial training does not (...
research
10/15/2020

Does Data Augmentation Benefit from Split BatchNorms

Data augmentation has emerged as a powerful technique for improving the ...
research
12/20/2021

Certified Federated Adversarial Training

In federated learning (FL), robust aggregation schemes have been develop...
research
09/13/2023

Deep Nonparametric Convexified Filtering for Computational Photography, Image Synthesis and Adversarial Defense

We aim to provide a general framework of for computational photography t...

Please sign up or login with your details

Forgot password? Click here to reset