DAT: Improving Adversarial Robustness via Generative Amplitude Mix-up in Frequency Domain

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Fengpeng, Li, Kemou, Wu, Haiwei, Tian, Jinyu, Zhou, Jiantao
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909351931805696
author Li, Fengpeng
Li, Kemou
Wu, Haiwei
Tian, Jinyu
Zhou, Jiantao
author_facet Li, Fengpeng
Li, Kemou
Wu, Haiwei
Tian, Jinyu
Zhou, Jiantao
contents To protect deep neural networks (DNNs) from adversarial attacks, adversarial training (AT) is developed by incorporating adversarial examples (AEs) into model training. Recent studies show that adversarial attacks disproportionately impact the patterns within the phase of the sample's frequency spectrum -- typically containing crucial semantic information -- more than those in the amplitude, resulting in the model's erroneous categorization of AEs. We find that, by mixing the amplitude of training samples' frequency spectrum with those of distractor images for AT, the model can be guided to focus on phase patterns unaffected by adversarial perturbations. As a result, the model's robustness can be improved. Unfortunately, it is still challenging to select appropriate distractor images, which should mix the amplitude without affecting the phase patterns. To this end, in this paper, we propose an optimized Adversarial Amplitude Generator (AAG) to achieve a better tradeoff between improving the model's robustness and retaining phase patterns. Based on this generator, together with an efficient AE production procedure, we design a new Dual Adversarial Training (DAT) strategy. Experiments on various datasets show that our proposed DAT leads to significantly improved robustness against diverse adversarial attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2410_12307
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle DAT: Improving Adversarial Robustness via Generative Amplitude Mix-up in Frequency Domain
Li, Fengpeng
Li, Kemou
Wu, Haiwei
Tian, Jinyu
Zhou, Jiantao
Machine Learning
Computer Vision and Pattern Recognition
To protect deep neural networks (DNNs) from adversarial attacks, adversarial training (AT) is developed by incorporating adversarial examples (AEs) into model training. Recent studies show that adversarial attacks disproportionately impact the patterns within the phase of the sample's frequency spectrum -- typically containing crucial semantic information -- more than those in the amplitude, resulting in the model's erroneous categorization of AEs. We find that, by mixing the amplitude of training samples' frequency spectrum with those of distractor images for AT, the model can be guided to focus on phase patterns unaffected by adversarial perturbations. As a result, the model's robustness can be improved. Unfortunately, it is still challenging to select appropriate distractor images, which should mix the amplitude without affecting the phase patterns. To this end, in this paper, we propose an optimized Adversarial Amplitude Generator (AAG) to achieve a better tradeoff between improving the model's robustness and retaining phase patterns. Based on this generator, together with an efficient AE production procedure, we design a new Dual Adversarial Training (DAT) strategy. Experiments on various datasets show that our proposed DAT leads to significantly improved robustness against diverse adversarial attacks.
title DAT: Improving Adversarial Robustness via Generative Amplitude Mix-up in Frequency Domain
topic Machine Learning
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2410.12307