错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ARE-CAM: An Interpretable Approach to Quantitatively Evaluating the Adversarial Robustness of Deep Models Based on CAM

  • Zituo Li,
  • Jianbin Sun,
  • Yuqi Qin,
  • Lunhao Ju,
  • Kewei Yang

摘要

Evaluating the adversarial robustness of deep models is critical for training more robust models. However, few methods are both interpretable and quantifiable. Interpretable evaluation methods cannot quantify adversarial robustness, leading to unobjective evaluation results. On the other hand, quantifiable evaluation methods are often unexplainable, making it difficult for evaluators to trust and trace the results. To address this issue, an adversarial robustness evaluation approach based on class activation mapping (ARE-CAM) is proposed. This approach utilizes CAM to generate heatmaps and visualize the areas of concern for the model. By comparing the difference between the original example and the adversarial example from the perspective of visual and statistical characteristics, the changes in the model after being attacked are observed, which enhances the interpretability of the evaluation. Additionally, four metrics are proposed to quantify adversarial robustness: the average coverage coincidence rate (ACCR), average high activation coincidence rate (AHCR), average heat area difference (AHAD) and average heat difference (AHD). Comprehensive experiments are conducted based on 14 deep models and different datasets to verify ARE-CAM’s efficiency. To the best of our knowledge, ARE-CAM is the first quantifiable and interpretable approach for evaluating adversarial robustness.