Improving robustness of convolutional neural networks using element-wise activation scaling

被引:4
|
作者
Zhang, Zhi-Yuan [1 ]
Ren, Hao [2 ]
He, Zhenli [1 ]
Zhou, Wei [1 ]
Liu, Di [3 ]
机构
[1] Yunnan Univ, Sch Software, Kunming 650500, Peoples R China
[2] Peoples Liberat Army Gen Hosp, Dept Informat, Med Supplies Ctr, Beijing 100853, Peoples R China
[3] Norwegian Univ Sci & Technol, Dept Comp Sci, N-7491 Trondheim, Norway
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2023年 / 149卷
关键词
Adversarial attack; Robustness; Convolutional Neural Networks; Element-Wise Scaling;
D O I
10.1016/j.future.2023.07.013
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recent works reveal that re-calibrating intermediate activation of adversarial examples can improve the adversarial robustness of CNN models. The state of the arts exploit this feature at the channel level to help CNN models defend adversarial attacks, where each intermediate activation is uniformly scaled by a factor. However, we conduct a more fine-grained analysis on intermediate activation and observe that adversarial examples only change a portion of elements within an activation. This observation motivates us to investigate a new method to re-calibrate intermediate activation of CNNs to improve robustness. Instead of uniformly scaling each activation, we individually adjust each element within an activation and thus propose Element-Wise Activation Scaling, dubbed EWAS, to improve CNNs' adversarial robustness. EWAS is a simple yet very effective method in enhancing robustness. Experimental results on ResNet-18 and WideResNet with CIFAR10 and SVHN show that EWAS significantly improves the robustness accuracy. Especially for ResNet18 on CIFAR10, EWAS increases the adversarial accuracy by 37.65% to 82.35% against C & W attack. The code and trained models are available at https://github.com/ieslab-ynu/EWAS.& COPY; 2023 Elsevier B.V. All rights reserved.
引用
收藏
页码:136 / 148
页数:13
相关论文
共 50 条
  • [1] Selection of element-wise shell kinematics using neural networks
    Petrolo, M.
    Carrera, E.
    COMPUTERS & STRUCTURES, 2021, 244
  • [2] ON THE ACCURACY AND EFFICIENCY OF CONVOLUTIONAL NEURAL NETWORKS FOR ELEMENT-WISE REFINEMENT OF FEM MODELS
    Petrolo, M.
    Iannotti, P.
    Pagani, A.
    Carrera, E.
    PROCEEDINGS OF ASME 2022 INTERNATIONAL MECHANICAL ENGINEERING CONGRESS AND EXPOSITION, IMECE2022, VOL 3, 2022,
  • [3] Sound event localization and detection using element-wise attention gate and asymmetric convolutional recurrent neural networks
    Yan, Lean
    Guo, Min
    Li, Zhiqiang
    AI COMMUNICATIONS, 2023, 36 (02) : 147 - 157
  • [4] Convolutional Neural Network with Element-wise Filters to Extract Hierarchical Topological Features for Brain Networks
    Xing, Xinying
    Ji, Junzhong
    Yao, Yao
    PROCEEDINGS 2018 IEEE INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOMEDICINE (BIBM), 2018, : 780 - 783
  • [5] Network Quantization with Element-wise Gradient Scaling
    Lee, Junghyup
    Kim, Dohyung
    Ham, Bumsub
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 6444 - 6453
  • [6] Convolutional Neural Network with an Element-wise Filter to Classify Dynamic Functional Connectivity
    Chen, Zhihui
    Ji, Junzhong
    Ling, Yin
    2019 IEEE INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOMEDICINE (BIBM), 2019, : 643 - 646
  • [7] Strategies for Improving the Error Robustness of Convolutional Neural Networks
    Morais, Antonio
    Barbosa, Raul
    Lourenco, Nuno
    Cerveira, Frederico
    Lombardi, Michele
    Madeira, Henrique
    2022 IEEE 22ND INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY, QRS, 2022, : 874 - 883
  • [8] Smart IoT Network Based Convolutional Recurrent Neural Network With Element-Wise Prediction System
    Al-Jamali, Nadia Adnan Shiltagh
    Al-Raweshidy, Hamed S.
    IEEE ACCESS, 2021, 9 : 47864 - 47874
  • [9] IMPROVING THE ROBUSTNESS OF CONVOLUTIONAL NEURAL NETWORKS VIA SKETCH ATTENTION
    Chu, Tianshu
    Yang, Zuopeng
    Yang, Jie
    Huang, Xiaolin
    2021 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2021, : 869 - 873
  • [10] Take CARE: Improving Inherent Robustness of Spiking Neural Networks with Channel-wise Activation Recalibration Module
    Zhang, Yan
    Chen, Cheng
    Shen, Dian
    Wang, Meng
    Wang, Beilun
    23RD IEEE INTERNATIONAL CONFERENCE ON DATA MINING, ICDM 2023, 2023, : 828 - 837