Adversarial Defense via Scatter and Alignment

Ying Zou, Chenglong Zhao, Shibin Mei, Bingbing Ni · 2020

Recently, adversarial examples have imposed a serious threat to the robustness of deep models and raise potential risks in AI-Security areas. To defend adversarial attacks, we develop a novel defense paradigm via embedding scatter and feature alignment to enhance model's robustness. We first propose a margin constraint loss to encourage better discriminative representations of samples, i.e., increasing inter-class distance and reducing intra-class distance simultaneously. Then a novel method is introduced to seek the representation anchors channel-wisely, which quantizes the learned representations into different scatters. During the inference stage, we first align the extracted representation from the input data onto the most similar anchors and use these anchors replace the representations. Finally, we rebuild and feed these aligned representations into the classifier to get the result. This novel paradigm for utilizing representation anchors channel-wisely provides a new viewpoint to understand the CNN's fragility. Extensive experiments on several datasets well demonstrate that the proposed method improves models' robustness without compromising performance.

Read the paper · More papers on PaperTik