CE \(^2\) : A Copula Entropic Mutual Information Estimator for Enhancing Adversarial Robustness
摘要
Deep neural networks are vulnerable to adversarial examples, which exploit imperceptible perturbations to mislead classifiers. To improve adversarial robustness, recent methods have focused on estimating mutual information (MI). However, existing MI estimators struggle to provide stable and reliable estimates in high-dimensional data. To this end, we propose a Copula Entropic MI Estimator (CE \(^2\) ) to address these limitations. CE \(^2\) leverages copula entropy to estimating MI in high dimensions, allowing target models to harness information from both clean and adversarial examples to withstand attacks. Our empirical experiments demonstrate that CE \(^2\) achieves a trade-off between variance and bias in MI estimates, resulting in stable and reliable estimates. Furthermore, the defense algorithm based on CE \(^2\) significantly enhances adversarial robustness against multiple attacks. The experimental results underscore the effectiveness of CE \(^2\) and its potential for improving adversarial robustness.