Towards Adversarial Robustness of Model-Level Mixture-of-Experts Architectures for Semantic Segmentation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Pavlitska, Svetlana, Eisen, Enrico, Zöllner, J. Marius
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915065790201856
author Pavlitska, Svetlana
Eisen, Enrico
Zöllner, J. Marius
author_facet Pavlitska, Svetlana
Eisen, Enrico
Zöllner, J. Marius
contents Vulnerability to adversarial attacks is a well-known deficiency of deep neural networks. Larger networks are generally more robust, and ensembling is one method to increase adversarial robustness: each model's weaknesses are compensated by the strengths of others. While an ensemble uses a deterministic rule to combine model outputs, a mixture of experts (MoE) includes an additional learnable gating component that predicts weights for the outputs of the expert models, thus determining their contributions to the final prediction. MoEs have been shown to outperform ensembles on specific tasks, yet their susceptibility to adversarial attacks has not been studied yet. In this work, we evaluate the adversarial vulnerability of MoEs for semantic segmentation of urban and highway traffic scenes. We show that MoEs are, in most cases, more robust to per-instance and universal white-box adversarial attacks and can better withstand transfer attacks. Our code is available at \url{https://github.com/KASTEL-MobilityLab/mixtures-of-experts/}.
format Preprint
id arxiv_https___arxiv_org_abs_2412_11608
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Towards Adversarial Robustness of Model-Level Mixture-of-Experts Architectures for Semantic Segmentation
Pavlitska, Svetlana
Eisen, Enrico
Zöllner, J. Marius
Computer Vision and Pattern Recognition
Machine Learning
Vulnerability to adversarial attacks is a well-known deficiency of deep neural networks. Larger networks are generally more robust, and ensembling is one method to increase adversarial robustness: each model's weaknesses are compensated by the strengths of others. While an ensemble uses a deterministic rule to combine model outputs, a mixture of experts (MoE) includes an additional learnable gating component that predicts weights for the outputs of the expert models, thus determining their contributions to the final prediction. MoEs have been shown to outperform ensembles on specific tasks, yet their susceptibility to adversarial attacks has not been studied yet. In this work, we evaluate the adversarial vulnerability of MoEs for semantic segmentation of urban and highway traffic scenes. We show that MoEs are, in most cases, more robust to per-instance and universal white-box adversarial attacks and can better withstand transfer attacks. Our code is available at \url{https://github.com/KASTEL-MobilityLab/mixtures-of-experts/}.
title Towards Adversarial Robustness of Model-Level Mixture-of-Experts Architectures for Semantic Segmentation
topic Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2412.11608