Dilated Denoising U-Net Network Improving the Adversarial Robustness

Xianshan Zhang, Fan Jia · Journal of Physics Conference Series · 2020

Abstract The adversarial attack generates adversarial samples by adding subtle perturbations to the image. Such perturbations are usually very small and undetectable, but the neural network will give completely different results from the real sample. Adversarial example completely fools the neural network. Therefore, it is very important to develop effective defending model. Convolutional neural networks have successfully achieved adversarial robustness by removing noise in adversarial samples. However, the convolutional neural network involves multiple layers, and the denoising model contains a large number of parameters. This paper proposes a dilated convolutional denoising U-Net network to remove adversarial sample noise. Compared with the previously proposed denoising U-Net, our model has fewer layers. Dilated convolution is used in the convolutional layer to expand the receptive field. Use zero padding to ensure that the output dimensions are consistent with the input dimensions We conducted experiments on the ImageNet dataset. The experiments show that the extended of the receptive field can enhance the ability of the U-Net network to capture detailed image information, enhance denoising performance, and effectively improve the robustness at a lower computing cost.

Read the paper · More papers on PaperTik