Wavelet regularization benefits adversarial training

被引:4
|
作者
Yan, Jun [1 ]
Yin, Huilin [1 ]
Zhao, Ziming [1 ]
Ge, Wancheng [1 ]
Zhang, Hao [1 ]
Rigoll, Gerhard [2 ]
机构
[1] Tongji Univ, Coll Elect & Informat Engn, 4800 Caoan Gonglu Rd, Shanghai 201804, Peoples R China
[2] Tech Univ Munich, Inst Human Machine Commun, 21 Arcisstr, D-80333 Munich, Germany
基金
中国国家自然科学基金;
关键词
Deep learning; Robustness; Adversarial training; Wavelet transform; Lipschitz constraint; ROBUSTNESS;
D O I
10.1016/j.ins.2023.119650
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Adversarial training methods are frequently-used empirical defense methods against adversarial examples. While many regularization techniques demonstrate effectiveness when combined with adversarial training, these methods typically work in the time domain. However, as the adversarial vulnerability can be considered a high-frequency phenomenon, it is crucial to regulate adversarially-trained neural network models in the frequency domain to capture low-frequency and high-frequency features. Neural networks must fully utilize the detailed local features extracted by their receptive field. To address these challenges, we conduct a theoretical analysis of the regularization properties of wavelets, which can enhance adversarial training. We propose a wavelet regularization method based on the Haar wavelet decomposition named Wavelet Average Pooling. This wavelet regularization module is integrated into a wide residual neural network to form a new model called WideWaveletResNet. On the CIFAR-10 and CIFAR-100 datasets, our proposed Adversarial Wavelet Training method demonstrates considerable robustness against different types of attacks. It confirms our assumption that our wavelet regularization method can enhance adversarial robustness, particularly in deep and wide neural networks. We present a detailed comparison of different wavelet base functions and conduct visualization experiments of the Frequency Principle (F-Principle) and interpretability to demonstrate the effectiveness of our method. The code is available on the open-source website: https://github .com /momo1986 / AdversarialWaveletTraining.
引用
收藏
页数:20
相关论文
共 50 条
  • [1] Adversarial Training with Orthogonal Regularization
    Yuksel, Oguz Kaan
    Baytas, Inci Meliha
    2020 28TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2020,
  • [2] ADVERSARIAL TRAINING WITH CHANNEL ATTENTION REGULARIZATION
    Cho, Seungju
    Byun, Junyoung
    Kwon, Myung-Joon
    Kim, Yoonji
    Kim, Changick
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 2996 - 3000
  • [3] Unifying Adversarial Training Algorithms with Data Gradient Regularization
    Ororbia, Alexander G., II
    Kifer, Daniel
    Giles, C. Lee
    NEURAL COMPUTATION, 2017, 29 (04) : 867 - 887
  • [4] Comparative Study of Adversarial Defenses: Adversarial Training and Regularization in Vision Transformers and CNNs
    Dingeto, Hiskias
    Kim, Juntae
    ELECTRONICS, 2024, 13 (13)
  • [5] Stabilizing Training of Generative Adversarial Networks through Regularization
    Roth, Kevin
    Lucchi, Aurelien
    Nowozin, Sebastian
    Hofmann, Thomas
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 30 (NIPS 2017), 2017, 30
  • [6] Consistency Regularization Helps Mitigate Robust Overfitting in Adversarial Training
    Shudong Zhang
    Haichang Gao
    Yunyi Zhou
    Zihui Wu
    Yiwen Tang
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, KSEM 2022, PT III, 2022, 13370 : 734 - 746
  • [7] Adversarial training regularization for negative sampling based network embedding
    Dai, Quanyu
    Shen, Xiao
    Zheng, Zimu
    Zhang, Liang
    Li, Qiang
    Wang, Dan
    INFORMATION SCIENCES, 2021, 579 : 199 - 217
  • [8] Adversarial Deformation Regularization for Training Image Registration Neural Networks
    Hu, Yipeng
    Gibson, Eli
    Ghavami, Nooshin
    Bonmati, Ester
    Moore, Caroline M.
    Emberton, Mark
    Vercauteren, Tom
    Noble, J. Alison
    Barratt, Dean C.
    MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION - MICCAI 2018, PT I, 2018, 11070 : 774 - 782
  • [9] An Adversarial Training Based Speech Emotion Classifier With Isolated Gaussian Regularization
    Fu, Changzeng
    Liu, Chaoran
    Ishi, Carlos Toshinori
    Ishiguro, Hiroshi
    IEEE TRANSACTIONS ON AFFECTIVE COMPUTING, 2023, 14 (03) : 2361 - 2374
  • [10] Adversarial Training for Code Retrieval with Question-Description Relevance Regularization
    Zhao, Jie
    Sun, Huan
    FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, EMNLP 2020, 2020, : 4049 - 4059