arXiv:2603.25244cs.CV2026-03

用图像锐化提升模型抗干扰能力,无需训练或优化。

Efficient Preemptive Robustification with Image Sharpening

  • 通过锐化图像增强鲁棒性,不依赖模型或生成器。
  • 在迁移场景中显著提升防御效果,计算开销极低。
  • 方法简单可解释,适合实际部署与快速防护。

尽管深度神经网络取得了巨大成功,但其依赖高维、非鲁棒的表示,容易受到难以察觉的扰动影响,甚至在迁移场景中也是如此。为应对这一问题,研究者提出了多种防御方法,包括训练阶段防御(如对抗训练和鲁棒架构设计)和攻击后防御(如输入净化和对抗检测)。近年来,有少量工作探索了预攻击防御范式——预置强化(preemptive robustification),即在攻击前对正常样本进行微调以主动抵抗对抗扰动。然而,其实际应用受限于三大缺陷:(1) 依赖已训练分类器作为代理提供鲁棒性先验;(2) 因迭代优化或训练生成器导致显著计算开销;(3) 优化或生成过程缺乏可解释性。受近期研究发现纹理强度与正常样本鲁棒性正相关的启发,我们证明仅通过图像锐化即可高效实现强化。据我们所知,这是首个无代理、无优化、无生成器且人类可解释的强化方法。大量实验表明,锐化在低计算成本下带来显著鲁棒性提升,尤其在迁移场景中表现优异。

原文摘要 · Abstract (English)

Despite their great success, deep neural networks rely on high-dimensional, non-robust representations, making them vulnerable to imperceptible perturbations, even in transfer scenarios. To address this, both training-time defenses (e.g., adversarial training and robust architecture design) and post-attack defenses (e.g., input purification and adversarial detection) have been extensively studied. Recently, a limited body of work has preliminarily explored a pre-attack defense paradigm, termed preemptive robustification, which introduces subtle modifications to benign samples prior to attack to proactively resist adversarial perturbations. Unfortunately, their practical applicability remains questionable due to several limitations, including (1) reliance on well-trained classifiers as surrogates to provide robustness priors, (2) substantial computational overhead arising from iterative optimization or trained generators for robustification, and (3) limited interpretability of the optimization- or generation-based robustification processes. Inspired by recent studies revealing a positive correlation between texture intensity and the robustness of benign samples, we show that image sharpening alone can efficiently robustify images. To the best of our knowledge, this is the first surrogate-free, optimization-free, generator-free, and human-interpretable robustification approach. Extensive experiments demonstrate that sharpening yields remarkable robustness gains with low computational cost, especially in transfer scenarios.

图像增强对抗防御鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。