提出新方法NAPPure,提升模型对模糊遮挡等非加性干扰的鲁棒性。
NAPPure: Adversarial Purification for Robust Image Classification under Non-Additive Perturbations
- 通过似然最大化分离图像与干扰参数
- 在GTSRB和CIFAR-10上显著提升抗非加性扰动能力
- 适合关注真实场景下模型鲁棒性的研究者
对抗净化在应对加性对抗扰动方面已取得显著成效,但现实中的非加性扰动(如模糊、遮挡、失真)仍普遍存在。现有方法因针对加性扰动设计,对非加性扰动效果较差。本文提出扩展的对抗净化框架NAPPure,首先建立对抗图像生成过程,再通过似然最大化分离原始清晰图像与扰动参数。在GTSRB和CIFAR-10数据集上的实验表明,NAPPure显著提升了图像分类模型对非加性扰动的鲁棒性。
原文摘要 · Abstract (English)
Adversarial purification has achieved great success in combating adversarial image perturbations, which are usually assumed to be additive. However, non-additive adversarial perturbations such as blur, occlusion, and distortion are also common in the real world. Under such perturbations, existing adversarial purification methods are much less effective since they are designed to fit the additive nature. In this paper, we propose an extended adversarial purification framework named NAPPure, which can further handle non-additive perturbations. Specifically, we first establish the generation process of an adversarial image, and then disentangle the underlying clean image and perturbation parameters through likelihood maximization. Experiments on GTSRB and CIFAR-10 datasets show that NAPPure significantly boosts the robustness of image classification models against non-additive perturbations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。