Improving robustness of convolutional neural networks using element-wise activation scaling

被引:5
作者
Zhang, Zhi-Yuan [1 ]
Ren, Hao [2 ]
He, Zhenli [1 ]
Zhou, Wei [1 ]
Liu, Di [3 ]
机构
[1] Yunnan Univ, Sch Software, Kunming 650500, Peoples R China
[2] Peoples Liberat Army Gen Hosp, Dept Informat, Med Supplies Ctr, Beijing 100853, Peoples R China
[3] Norwegian Univ Sci & Technol, Dept Comp Sci, N-7491 Trondheim, Norway
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2023年 / 149卷
关键词
Adversarial attack; Robustness; Convolutional Neural Networks; Element-Wise Scaling;
D O I
10.1016/j.future.2023.07.013
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recent works reveal that re-calibrating intermediate activation of adversarial examples can improve the adversarial robustness of CNN models. The state of the arts exploit this feature at the channel level to help CNN models defend adversarial attacks, where each intermediate activation is uniformly scaled by a factor. However, we conduct a more fine-grained analysis on intermediate activation and observe that adversarial examples only change a portion of elements within an activation. This observation motivates us to investigate a new method to re-calibrate intermediate activation of CNNs to improve robustness. Instead of uniformly scaling each activation, we individually adjust each element within an activation and thus propose Element-Wise Activation Scaling, dubbed EWAS, to improve CNNs' adversarial robustness. EWAS is a simple yet very effective method in enhancing robustness. Experimental results on ResNet-18 and WideResNet with CIFAR10 and SVHN show that EWAS significantly improves the robustness accuracy. Especially for ResNet18 on CIFAR10, EWAS increases the adversarial accuracy by 37.65% to 82.35% against C & W attack. The code and trained models are available at https://github.com/ieslab-ynu/EWAS.& COPY; 2023 Elsevier B.V. All rights reserved.
引用
收藏
页码:136 / 148
页数:13
相关论文
共 46 条
[1]   Enhancing the Robustness of Visual Object Tracking via Style Transfer [J].
Amirkhani, Abdollah ;
Barshooi, Amir Hossein ;
Ebrahimi, Amir .
CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 70 (01) :981-997
[2]   Square Attack: A Query-Efficient Black-Box Adversarial Attack via Random Search [J].
Andriushchenko, Maksym ;
Croce, Francesco ;
Flammarion, Nicolas ;
Hein, Matthias .
COMPUTER VISION - ECCV 2020, PT XXIII, 2020, 12368 :484-501
[3]  
Bai Y., 2021, 9 INT C LEARN REPR I, P1
[4]   A novel data augmentation based on Gabor filter and convolutional deep learning for improving the classification of COVID-19 chest X-Ray images [J].
Barshooi, Amir Hossein ;
Amirkhani, Abdollah .
BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2022, 72
[5]   Towards Evaluating the Robustness of Neural Networks [J].
Carlini, Nicholas ;
Wagner, David .
2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, :39-57
[6]  
Chakraborty A, 2018, Arxiv, DOI arXiv:1810.00069
[7]  
Chen HL, 2019, PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, P4658
[8]  
Chen PY, 2017, PROCEEDINGS OF THE 10TH ACM WORKSHOP ON ARTIFICIAL INTELLIGENCE AND SECURITY, AISEC 2017, P15, DOI 10.1145/3128572.3140448
[9]  
Croce F, 2020, PR MACH LEARN RES, V119
[10]   An Analysis of Adversarial Attacks and Defenses on Autonomous Driving Models [J].
Deng, Yao ;
Zheng, Xi ;
Zhang, Tianyi ;
Chen, Chen ;
Lou, Guannan ;
Kim, Miryung .
2020 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS (PERCOM 2020), 2020,