article

Attention, Please! Adversarial Defense via Activation Rectification and Preservation

  • ACM Transactions on Multimedia Computing Communications and Applications
  • Association for Computing Machinery
Research footprint

At a glance

Citations
7
References
20
Comments
0
Paper overview

Abstract

This study provides a new understanding of the adversarial attack problem by examining the correlation between adversarial attack and visual attention change. In particular, we observed that: (1) images with incomplete attention regions are more vulnerable to adversarial attacks; and (2) successful adversarial attacks lead to deviated and scattered activation map. Therefore, we use the mask method to design an attention-preserving loss and a contrast method to design a loss that makes the model’s attention rectification. Accordingly, an attention-based adversarial defense framework is designed, under which better adversarial training or stronger adversarial attacks can be performed through the above constraints. We hope the attention-related data analysis and defense solution in this study will shed some light on the mechanism behind the adversarial attack and also facilitate future adversarial defense/attack model design.

Record transparency

Publication details

DOI
10.1145/3572843
OpenAlex
W4310988119
Document type
article
Language
EN
Source
ACM Transactions on Multimedia Computing Communications and Applications
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.