Enhancing Adversarial Training with Prior Knowledge Distillation for Robust Image Compression

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cao, Zhi, Bao, Youneng, Meng, Fanyang, Li, Chao, Tan, Wen, Wang, Genhong, Liang, Yongsheng
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914715756658688
author Cao, Zhi
Bao, Youneng
Meng, Fanyang
Li, Chao
Tan, Wen
Wang, Genhong
Liang, Yongsheng
author_facet Cao, Zhi
Bao, Youneng
Meng, Fanyang
Li, Chao
Tan, Wen
Wang, Genhong
Liang, Yongsheng
contents Deep neural network-based image compression (NIC) has achieved excellent performance, but NIC method models have been shown to be susceptible to backdoor attacks. Adversarial training has been validated in image compression models as a common method to enhance model robustness. However, the improvement effect of adversarial training on model robustness is limited. In this paper, we propose a prior knowledge-guided adversarial training framework for image compression models. Specifically, first, we propose a gradient regularization constraint for training robust teacher models. Subsequently, we design a knowledge distillation based strategy to generate a priori knowledge from the teacher model to the student model for guiding adversarial training. Experimental results show that our method improves the reconstruction quality by about 9dB when the Kodak dataset is elected as the backdoor attack object for psnr attack. Compared with Ma2023, our method has a 5dB higher PSNR output at high bitrate points.
format Preprint
id arxiv_https___arxiv_org_abs_2403_06700
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Enhancing Adversarial Training with Prior Knowledge Distillation for Robust Image Compression
Cao, Zhi
Bao, Youneng
Meng, Fanyang
Li, Chao
Tan, Wen
Wang, Genhong
Liang, Yongsheng
Image and Video Processing
Deep neural network-based image compression (NIC) has achieved excellent performance, but NIC method models have been shown to be susceptible to backdoor attacks. Adversarial training has been validated in image compression models as a common method to enhance model robustness. However, the improvement effect of adversarial training on model robustness is limited. In this paper, we propose a prior knowledge-guided adversarial training framework for image compression models. Specifically, first, we propose a gradient regularization constraint for training robust teacher models. Subsequently, we design a knowledge distillation based strategy to generate a priori knowledge from the teacher model to the student model for guiding adversarial training. Experimental results show that our method improves the reconstruction quality by about 9dB when the Kodak dataset is elected as the backdoor attack object for psnr attack. Compared with Ma2023, our method has a 5dB higher PSNR output at high bitrate points.
title Enhancing Adversarial Training with Prior Knowledge Distillation for Robust Image Compression
topic Image and Video Processing
url https://arxiv.org/abs/2403.06700