Perceptually-Inspired Local Source Normalization for Adversarial Robustness
At a glance
- Citations
- 0
- References
- 13
- Comments
- 0
Abstract
The importance of the robustness of deep neural networks (DNNs) cannot be overemphasised due to their widespread use in safety-critical applications. However, the fragility of DNNs to imperceptible input perturbations is well-known in the literature. This fragility has led to the design of several attack and defense mechanisms aimed at building robust DNNs. The imperceptibility of adversarial DNN attacks motivated us to draw inspiration from the robust functioning of the human visual system (HVS). Specifically, we propose HVS-inspired local source normalisation as a simple yet effective technique to build robust DNNs. The efficacy of our method against classical and state-of-the-art attacks is demonstrated quantitatively and qualitatively. We apply the proposed method to popular DNNs such as ResNet-20, ResNet-56, and WideResNet-22-10 on the CIFAR-10 and CIFAR-100 datasets, and demonstrate quantitative improvement in accuracy for a majority of cases. Qualitatively, we analyze feature representations and class activation maps to highlight better feature separation, especially at higher attack levels. The proposed approach is simple, has few parameters, is attack-agnostic and can be adopted as a pre-processing technique for training DNNs.
Publication details
- DOI
- 10.1145/3639856.3639869
- OpenAlex
- W4397026683
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.