Test-Time Defense Against Adversarial Attacks via Stochastic Resonance of Latent Ensembles

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Lao, Dong, Zhang, Yuxiang, Oskouie, Haniyeh Ehsani, Wu, Yangchao, Wong, Alex, Soatto, Stefano
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866908574703157248
author Lao, Dong
Zhang, Yuxiang
Oskouie, Haniyeh Ehsani
Wu, Yangchao
Wong, Alex
Soatto, Stefano
author_facet Lao, Dong
Zhang, Yuxiang
Oskouie, Haniyeh Ehsani
Wu, Yangchao
Wong, Alex
Soatto, Stefano
contents We propose a test-time defense mechanism against adversarial attacks: imperceptible image perturbations that significantly alter the predictions of a model. Unlike existing methods that rely on feature filtering or smoothing, which can lead to information loss, we propose to "combat noise with noise" by leveraging stochastic resonance to enhance robustness while minimizing information loss. Our approach introduces small translational perturbations to the input image, aligns the transformed feature embeddings, and aggregates them before mapping back to the original reference image. This can be expressed in a closed-form formula, which can be deployed on diverse existing network architectures without introducing additional network modules or fine-tuning for specific attack types. The resulting method is entirely training-free, architecture-agnostic, and attack-agnostic. Empirical results show state-of-the-art robustness on image classification and, for the first time, establish a generic test-time defense for dense prediction tasks, including stereo matching and optical flow, highlighting the method's versatility and practicality. Specifically, relative to clean (unperturbed) performance, our method recovers up to 68.1% of the accuracy loss on image classification, 71.9% on stereo matching, and 29.2% on optical flow under various types of adversarial attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2510_03224
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Test-Time Defense Against Adversarial Attacks via Stochastic Resonance of Latent Ensembles
Lao, Dong
Zhang, Yuxiang
Oskouie, Haniyeh Ehsani
Wu, Yangchao
Wong, Alex
Soatto, Stefano
Computer Vision and Pattern Recognition
Artificial Intelligence
Machine Learning
We propose a test-time defense mechanism against adversarial attacks: imperceptible image perturbations that significantly alter the predictions of a model. Unlike existing methods that rely on feature filtering or smoothing, which can lead to information loss, we propose to "combat noise with noise" by leveraging stochastic resonance to enhance robustness while minimizing information loss. Our approach introduces small translational perturbations to the input image, aligns the transformed feature embeddings, and aggregates them before mapping back to the original reference image. This can be expressed in a closed-form formula, which can be deployed on diverse existing network architectures without introducing additional network modules or fine-tuning for specific attack types. The resulting method is entirely training-free, architecture-agnostic, and attack-agnostic. Empirical results show state-of-the-art robustness on image classification and, for the first time, establish a generic test-time defense for dense prediction tasks, including stereo matching and optical flow, highlighting the method's versatility and practicality. Specifically, relative to clean (unperturbed) performance, our method recovers up to 68.1% of the accuracy loss on image classification, 71.9% on stereo matching, and 29.2% on optical flow under various types of adversarial attacks.
title Test-Time Defense Against Adversarial Attacks via Stochastic Resonance of Latent Ensembles
topic Computer Vision and Pattern Recognition
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2510.03224