Interpretability-Guided Test-Time Adversarial Defense

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Kulkarni, Akshay, Weng, Tsui-Wei
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912041398173696
author Kulkarni, Akshay
Weng, Tsui-Wei
author_facet Kulkarni, Akshay
Weng, Tsui-Wei
contents We propose a novel and low-cost test-time adversarial defense by devising interpretability-guided neuron importance ranking methods to identify neurons important to the output classes. Our method is a training-free approach that can significantly improve the robustness-accuracy tradeoff while incurring minimal computational overhead. While being among the most efficient test-time defenses (4x faster), our method is also robust to a wide range of black-box, white-box, and adaptive attacks that break previous test-time defenses. We demonstrate the efficacy of our method for CIFAR10, CIFAR100, and ImageNet-1k on the standard RobustBench benchmark (with average gains of 2.6%, 4.9%, and 2.8% respectively). We also show improvements (average 1.5%) over the state-of-the-art test-time defenses even under strong adaptive attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2409_15190
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Interpretability-Guided Test-Time Adversarial Defense
Kulkarni, Akshay
Weng, Tsui-Wei
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
We propose a novel and low-cost test-time adversarial defense by devising interpretability-guided neuron importance ranking methods to identify neurons important to the output classes. Our method is a training-free approach that can significantly improve the robustness-accuracy tradeoff while incurring minimal computational overhead. While being among the most efficient test-time defenses (4x faster), our method is also robust to a wide range of black-box, white-box, and adaptive attacks that break previous test-time defenses. We demonstrate the efficacy of our method for CIFAR10, CIFAR100, and ImageNet-1k on the standard RobustBench benchmark (with average gains of 2.6%, 4.9%, and 2.8% respectively). We also show improvements (average 1.5%) over the state-of-the-art test-time defenses even under strong adaptive attacks.
title Interpretability-Guided Test-Time Adversarial Defense
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2409.15190