Deep neural networks (DNNs) are vulnerable to adversarial example attacks, which pose a potential threat to safety-sensitive autonomous driving. Previous research on adversarial defense mainly concentrates on modifying DNN models, preprocessing adversarial examples, and detecting adversarial examples. However, these methods usually suffer from limited defense effectiveness, lacking a well-defined and robust boundary. To tackle these problems, we propose a novel adversarial defense mechanism, ImgQuant, which enhances model adversarial robustness through dual-image quantization. Compared with existing methods, ImgQuant has two competitive advantages. First, it diminishes the adversary’s search space by squeezing unnecessary input details, thereby shrinking the living space of adversarial examples and improving the adversarial robustness of the model. Second, we implement dual-image quantization through a client-server communication model to establish a robust security boundary for ImgQuant. This ensures the elimination of adversarial noise as long as the perturbation magnitude \(\epsilon \) does not exceed the boundary. Our proposed ImgQuant is comprehensively verified on universal datasets and extended to real road sign recognition. Extensive experiments show that ImgQuant has an identical high accuracy within the robust security boundary under various attacks, and can also be used to improve the performance of adversarial training.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ImgQuant: Towards Adversarial Defense with Robust Boundary via Dual-Image Quantization

  • Huanhuan Lv,
  • Songru Jiang,
  • Tuohang Wan,
  • Lijun Chen

摘要

Deep neural networks (DNNs) are vulnerable to adversarial example attacks, which pose a potential threat to safety-sensitive autonomous driving. Previous research on adversarial defense mainly concentrates on modifying DNN models, preprocessing adversarial examples, and detecting adversarial examples. However, these methods usually suffer from limited defense effectiveness, lacking a well-defined and robust boundary. To tackle these problems, we propose a novel adversarial defense mechanism, ImgQuant, which enhances model adversarial robustness through dual-image quantization. Compared with existing methods, ImgQuant has two competitive advantages. First, it diminishes the adversary’s search space by squeezing unnecessary input details, thereby shrinking the living space of adversarial examples and improving the adversarial robustness of the model. Second, we implement dual-image quantization through a client-server communication model to establish a robust security boundary for ImgQuant. This ensures the elimination of adversarial noise as long as the perturbation magnitude \(\epsilon \) does not exceed the boundary. Our proposed ImgQuant is comprehensively verified on universal datasets and extended to real road sign recognition. Extensive experiments show that ImgQuant has an identical high accuracy within the robust security boundary under various attacks, and can also be used to improve the performance of adversarial training.