arXiv:2502.00834cs.LGcs.CR2025-02被引 1

通过结构先验提升模型抗攻击能力和泛化性能

Boosting Adversarial Robustness and Generalization with Structural Prior

  • 在残差网络中引入弹性字典学习机制
  • 在RobustBench上显著超越现有基线方法
  • 首次验证结构先验可增强强自适应攻击下的鲁棒性

本文提出一种新方法,通过在深度学习模型设计中引入结构先验,以提升对抗鲁棒性和泛化能力。研究发现,现有的字典学习启发的卷积神经网络(CNN)对对抗攻击存在虚假安全感。为此,我们提出弹性字典学习网络(EDLNet),一种新型残差网络架构,在理论上通过影响函数分析证明其鲁棒性,并在包括RobustBench在内的多个公开基准上展现出一致且显著的性能提升,超越当前最优基线。据我们所知,这是首个发现并验证结构先验能在强自适应攻击下可靠提升深度学习鲁棒性的研究,为未来研究开辟了新方向。

原文摘要 · Abstract (English)

This work investigates a novel approach to boost adversarial robustness and generalization by incorporating structural prior into the design of deep learning models. Specifically, our study surprisingly reveals that existing dictionary learning-inspired convolutional neural networks (CNNs) provide a false sense of security against adversarial attacks. To address this, we propose Elastic Dictionary Learning Networks (EDLNets), a novel ResNet architecture that significantly enhances adversarial robustness and generalization. This novel and effective approach is supported by a theoretical robustness analysis using influence functions. Moreover, extensive and reliable experiments demonstrate consistent and significant performance improvement on open robustness leaderboards such as RobustBench, surpassing state-of-the-art baselines. To the best of our knowledge, this is the first work to discover and validate that structural prior can reliably enhance deep learning robustness under strong adaptive attacks, unveiling a promising direction for future research.

对抗鲁棒性结构先验深度学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。