错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

RobustFace: a novel image restoration technique for face adversarial robustness improvement

  • Chiranjeevi Sadu,
  • Pradip K. Das,
  • V Ramanjaneyulu Yannam,
  • Anand Nayyar

摘要

Machine Learning (ML) models, particularly Deep Learning (DL), have made rapid progress and achieved significant milestones across various applications, including numerous safety-critical contexts. However, these models have recently been discovered to be susceptible to adversarial attacks, which are well-crafted input images. The primary objective of this paper is to propose a novel methodology titled “RobustFace“, which is based on deep image restoration networks, that significantly improves the facial adversarial robustness of various image-classification models. Adversarial images are created using the Private Fast Gradient Sign Method (P-FGSM), StyleGAN and Fast Landmark Manipulation (FLM) methods. The adversarial images are then enhanced using deep image restoration networks to bring back them into the original space. The encoded weighted local magnitude patterns (WLMP) are extracted and provided to different types of classifiers to detect facial adversarial images from the clean images. The effectiveness of RobustFace has been demonstrated on two real-world datasets and experimental outcomes show that it significantly improves facial adversarial robustness on all evaluating classifiers. It improves the highest classification accuracy from \({\textbf {98.75}}\%\) 98.75 % to \({\textbf {99.00}}\%\) 99.00 % on P-FGSM attacks, from \({\textbf {77.94}}\%\) 77.94 % to \({\textbf {85.25}}\%\) 85.25 % on adversarial attacks generated by StyleGAN and from \({\textbf {65.52}}\%\) 65.52 % to \({\textbf {69.50}}\%\) 69.50 % for FLM attacks.