Semantic-Aware Adversarial Training
摘要
Recent investigations into adversarial deep hashing networks have underscored the security threat posed by adversarial examples, known as adversarial vulnerability. Effectively distilling reliable semantic representatives for deep hashing to guide adversarial learning proves challenging, impeding the improvement of adversarial robustness in deep hashing-based retrieval models. Additionally, existing research on adversarial training for deep hashing lacks a unified minimax structure. This chapter introduces Semantic-Aware Adversarial Training (SAATSemantic-Aware Adversarial Training (SAAT)) to enhance the adversarial robustness of deep hashing models. A discriminative mainstay features learning (DMFLDiscriminative mainstay features learning (DMFL)) scheme is conceived to construct semantic representatives for guiding adversarial learning in deep hashing. DMFLDiscriminative mainstay features learning (DMFL), with a strict theoretical guarantee, is adaptively optimized in a discriminative learning manner, considering both discriminative and semantic properties jointly. Adversarial examples are generated by maximizing the Hamming distance between hash codes of adversarial samples and mainstay features, validated for efficacy in adversarial attack trials. Notably, this chapter formulates the formalized adversarial training of deep hashing into a unified minimax optimization for the first time, guided by generated mainstay codes. Extensive experiments on benchmark datasets demonstrate superb attack performance against state-of-the-art algorithms, while the proposed adversarial training effectively eliminates adversarial perturbations, ensuring trustworthy deep hashing-based retrieval.