Evaluating Adversarial Robustness in the Spatial Frequency Domain

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Liao, Keng-Hsin, Yeh, Chin-Yuan, Chen, Hsi-Wen, Chen, Ming-Syan
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866916241774477312
author Liao, Keng-Hsin
Yeh, Chin-Yuan
Chen, Hsi-Wen
Chen, Ming-Syan
author_facet Liao, Keng-Hsin
Yeh, Chin-Yuan
Chen, Hsi-Wen
Chen, Ming-Syan
contents Convolutional Neural Networks (CNNs) have dominated the majority of computer vision tasks. However, CNNs' vulnerability to adversarial attacks has raised concerns about deploying these models to safety-critical applications. In contrast, the Human Visual System (HVS), which utilizes spatial frequency channels to process visual signals, is immune to adversarial attacks. As such, this paper presents an empirical study exploring the vulnerability of CNN models in the frequency domain. Specifically, we utilize the discrete cosine transform (DCT) to construct the Spatial-Frequency (SF) layer to produce a block-wise frequency spectrum of an input image and formulate Spatial Frequency CNNs (SF-CNNs) by replacing the initial feature extraction layers of widely-used CNN backbones with the SF layer. Through extensive experiments, we observe that SF-CNN models are more robust than their CNN counterparts under both white-box and black-box attacks. To further explain the robustness of SF-CNNs, we compare the SF layer with a trainable convolutional layer with identical kernel sizes using two mixing strategies to show that the lower frequency components contribute the most to the adversarial robustness of SF-CNNs. We believe our observations can guide the future design of robust CNN models.
format Preprint
id arxiv_https___arxiv_org_abs_2405_06345
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Evaluating Adversarial Robustness in the Spatial Frequency Domain
Liao, Keng-Hsin
Yeh, Chin-Yuan
Chen, Hsi-Wen
Chen, Ming-Syan
Computer Vision and Pattern Recognition
Convolutional Neural Networks (CNNs) have dominated the majority of computer vision tasks. However, CNNs' vulnerability to adversarial attacks has raised concerns about deploying these models to safety-critical applications. In contrast, the Human Visual System (HVS), which utilizes spatial frequency channels to process visual signals, is immune to adversarial attacks. As such, this paper presents an empirical study exploring the vulnerability of CNN models in the frequency domain. Specifically, we utilize the discrete cosine transform (DCT) to construct the Spatial-Frequency (SF) layer to produce a block-wise frequency spectrum of an input image and formulate Spatial Frequency CNNs (SF-CNNs) by replacing the initial feature extraction layers of widely-used CNN backbones with the SF layer. Through extensive experiments, we observe that SF-CNN models are more robust than their CNN counterparts under both white-box and black-box attacks. To further explain the robustness of SF-CNNs, we compare the SF layer with a trainable convolutional layer with identical kernel sizes using two mixing strategies to show that the lower frequency components contribute the most to the adversarial robustness of SF-CNNs. We believe our observations can guide the future design of robust CNN models.
title Evaluating Adversarial Robustness in the Spatial Frequency Domain
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2405.06345