Adversarial purification of information masking

Sitong Liu, Zhichao Lian, Shuangquan Zhang, Liang Xiao · Neurocomputing · 2024

Adversarial attacks meticulously generate minuscule, imperceptible perturbations that add to images to deceive neural networks . Adversarial purification methods seek to remove perturbations using generative models to achieve defense. However, residual perturbations lead to less-than-ideal results. Under the premise that perturbations are difficult to remove completely, we are the first to quantify the hazards of residual perturbations and explore how to achieve more robust defenses by reducing perturbations and resisting the impact of residual perturbations. Motivated by this, we propose a novel adversarial purification approach named Information Mask Purification (IMPure). Our method utilizes informative masks and a regional intersection reconstruction to generate images to reduce the perturbation residues. During training, we use the combination module to guide the generative model in recovering feature representations. Finally, we establish a combined constraint of pixel loss and perceptual loss to augment the model’s reconstruction adaptability. Extensive experiments on the complex dataset ImageNet with classifier models demonstrate that our approach achieves state-of-the-art results in defending against adversarial attack methods. Implementation code and pre-trained weights can be accessed at https://github.com/NoWindButRain/IMPure .

Read the paper · More papers on PaperTik