AFD: Mitigating Feature Gap for Adversarial Robustness by Feature Disentanglement

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhou, Nuoyan, Zhou, Dawei, Liu, Decheng, Wang, Nannan, Gao, Xinbo
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916515939352576
author Zhou, Nuoyan
Zhou, Dawei
Liu, Decheng
Wang, Nannan
Gao, Xinbo
author_facet Zhou, Nuoyan
Zhou, Dawei
Liu, Decheng
Wang, Nannan
Gao, Xinbo
contents Adversarial fine-tuning methods enhance adversarial robustness via fine-tuning the pre-trained model in an adversarial training manner. However, we identify that some specific latent features of adversarial samples are confused by adversarial perturbation and lead to an unexpectedly increasing gap between features in the last hidden layer of natural and adversarial samples. To address this issue, we propose a disentanglement-based approach to explicitly model and further remove the specific latent features. We introduce a feature disentangler to separate out the specific latent features from the features of the adversarial samples, thereby boosting robustness by eliminating the specific latent features. Besides, we align clean features in the pre-trained model with features of adversarial samples in the fine-tuned model, to benefit from the intrinsic features of natural samples. Empirical evaluations on three benchmark datasets demonstrate that our approach surpasses existing adversarial fine-tuning methods and adversarial training baselines.
format Preprint
id arxiv_https___arxiv_org_abs_2401_14707
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle AFD: Mitigating Feature Gap for Adversarial Robustness by Feature Disentanglement
Zhou, Nuoyan
Zhou, Dawei
Liu, Decheng
Wang, Nannan
Gao, Xinbo
Computer Vision and Pattern Recognition
Artificial Intelligence
Machine Learning
Adversarial fine-tuning methods enhance adversarial robustness via fine-tuning the pre-trained model in an adversarial training manner. However, we identify that some specific latent features of adversarial samples are confused by adversarial perturbation and lead to an unexpectedly increasing gap between features in the last hidden layer of natural and adversarial samples. To address this issue, we propose a disentanglement-based approach to explicitly model and further remove the specific latent features. We introduce a feature disentangler to separate out the specific latent features from the features of the adversarial samples, thereby boosting robustness by eliminating the specific latent features. Besides, we align clean features in the pre-trained model with features of adversarial samples in the fine-tuned model, to benefit from the intrinsic features of natural samples. Empirical evaluations on three benchmark datasets demonstrate that our approach surpasses existing adversarial fine-tuning methods and adversarial training baselines.
title AFD: Mitigating Feature Gap for Adversarial Robustness by Feature Disentanglement
topic Computer Vision and Pattern Recognition
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2401.14707