Adversarial Training of Deep Neural Networks Guided by Texture and Structural Information

被引:2
作者
Wang, Zhaoxin [1 ]
Wang, Handing [1 ]
Tian, Cong [1 ]
Jin, Yaochu [2 ]
机构
[1] Xidian Univ, Xian, Shaanxi, Peoples R China
[2] Bielefeld Univ, Bielefeld, Germany
来源
PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023 | 2023年
基金
中国国家自然科学基金;
关键词
Deep neural networks; adversarial training; structure and texture information;
D O I
10.1145/3581783.3612163
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training (AT) is one of the most effective ways for deep neural network models to resist adversarial examples. However, there is still a significant gap between robust training accuracy and testing accuracy. Although recent studies have shown that data augmentation can effectively reduce this gap, most methods heavily rely on generating large amounts of training data without considering which features are beneficial for model robustness, making them inefficient. To address the above issue, we propose a two-stage AT algorithm for image data that adopts different data augmentation strategies during the training process to improve model robustness. In the first stage, we focus on the convergence of the algorithm, which uses structure and texture information to guide AT. In the second stage, we introduce a strategy that randomly fuses the data features to generate diverse adversarial examples for AT. We compare our proposed algorithm with five state-of-the-art algorithms on three models, and the experimental results achieve the best robust accuracy under all evaluation metrics on the CIFAR10 dataset, demonstrating the superiority of our method.
引用
收藏
页码:4958 / 4967
页数:10
相关论文
共 50 条
[41]   Rethinking the Inception Architecture for Computer Vision [J].
Szegedy, Christian ;
Vanhoucke, Vincent ;
Ioffe, Sergey ;
Shlens, Jon ;
Wojna, Zbigniew .
2016 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2016, :2818-2826
[42]  
Wang Wenqi, 2019, COMPUTATION LANGUAGE
[43]  
Wang Zekai, 2023, Better diffusion models further improve adversarial training
[44]  
Wu Dongxian, 2020, Neural Information Processing Systems
[45]  
Xie Cihang, 2017, ARXIV COMPUTER VISIO
[46]  
Zagoruyko Sergey, 2016, ARXIV COMPUTER VISIO
[47]   Visualizing and Understanding Convolutional Networks [J].
Zeiler, Matthew D. ;
Fergus, Rob .
COMPUTER VISION - ECCV 2014, PT I, 2014, 8689 :818-833
[48]  
Zhang H., 2018, P INT C LEARN REPR
[49]  
Zhang HY, 2019, PR MACH LEARN RES, V97
[50]  
Zhang Tianyuan, 2019, INT C MACH LEARN