Towards Reliable Evaluation and Fast Training of Robust Semantic Segmentation Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Croce, Francesco, Singh, Naman D, Hein, Matthias
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913432981209088
author Croce, Francesco
Singh, Naman D
Hein, Matthias
author_facet Croce, Francesco
Singh, Naman D
Hein, Matthias
contents Adversarial robustness has been studied extensively in image classification, especially for the $\ell_\infty$-threat model, but significantly less so for related tasks such as object detection and semantic segmentation, where attacks turn out to be a much harder optimization problem than for image classification. We propose several problem-specific novel attacks minimizing different metrics in accuracy and mIoU. The ensemble of our attacks, SEA, shows that existing attacks severely overestimate the robustness of semantic segmentation models. Surprisingly, existing attempts of adversarial training for semantic segmentation models turn out to be weak or even completely non-robust. We investigate why previous adaptations of adversarial training to semantic segmentation failed and show how recently proposed robust ImageNet backbones can be used to obtain adversarially robust semantic segmentation models with up to six times less training time for PASCAL-VOC and the more challenging ADE20k. The associated code and robust models are available at https://github.com/nmndeep/robust-segmentation
format Preprint
id arxiv_https___arxiv_org_abs_2306_12941
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Towards Reliable Evaluation and Fast Training of Robust Semantic Segmentation Models
Croce, Francesco
Singh, Naman D
Hein, Matthias
Computer Vision and Pattern Recognition
Machine Learning
Adversarial robustness has been studied extensively in image classification, especially for the $\ell_\infty$-threat model, but significantly less so for related tasks such as object detection and semantic segmentation, where attacks turn out to be a much harder optimization problem than for image classification. We propose several problem-specific novel attacks minimizing different metrics in accuracy and mIoU. The ensemble of our attacks, SEA, shows that existing attacks severely overestimate the robustness of semantic segmentation models. Surprisingly, existing attempts of adversarial training for semantic segmentation models turn out to be weak or even completely non-robust. We investigate why previous adaptations of adversarial training to semantic segmentation failed and show how recently proposed robust ImageNet backbones can be used to obtain adversarially robust semantic segmentation models with up to six times less training time for PASCAL-VOC and the more challenging ADE20k. The associated code and robust models are available at https://github.com/nmndeep/robust-segmentation
title Towards Reliable Evaluation and Fast Training of Robust Semantic Segmentation Models
topic Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2306.12941