Advancing Adversarial Training by Injecting Booster Signal.

IEEE Trans Neural Netw Learn Syst

Published: September 2024

AI Article Synopsis

  • Recent research shows that deep neural networks (DNNs) are prone to adversarial attacks, and adversarial training (AT) is one of the most effective defenses but can compromise natural accuracy.
  • The proposed method introduces an external booster signal, which is added to images without overlapping with the original content, enhancing both adversarial robustness and natural accuracy.
  • Experimental findings indicate that this booster signal improves model performance beyond traditional AT and can be integrated into existing AT methods in a flexible manner.

Article Abstract

Recent works have demonstrated that deep neural networks (DNNs) are highly vulnerable to adversarial attacks. To defend against adversarial attacks, many defense strategies have been proposed, among which adversarial training (AT) has been demonstrated to be the most effective strategy. However, it has been known that AT sometimes hurts natural accuracy. Then, many works focus on optimizing model parameters to handle the problem. Different from the previous approaches, in this article, we propose a new approach to improve the adversarial robustness using an external signal rather than model parameters. In the proposed method, a well-optimized universal external signal called a booster signal is injected into the outside of the image which does not overlap with the original content. Then, it boosts both adversarial robustness and natural accuracy. The booster signal is optimized in parallel to model parameters step by step collaboratively. Experimental results show that the booster signal can improve both the natural and robust accuracies over the recent state-of-the-art AT methods. Also, optimizing the booster signal is general and flexible enough to be adopted on any existing AT methods.

Download full-text PDF

Source
http://dx.doi.org/10.1109/TNNLS.2023.3264256DOI Listing

Publication Analysis

Top Keywords

booster signal
20
model parameters
12
adversarial training
8
adversarial attacks
8
natural accuracy
8
adversarial robustness
8
external signal
8
signal
7
booster
5
adversarial
5

Similar Publications

Want AI Summaries of new PubMed Abstracts delivered to your In-box?

Enter search terms and have AI summaries delivered each week - change queries or unsubscribe any time!