Subspace Defense: Discarding Adversarial Perturbations by Learning a Subspace for Clean Signals
Zheng, Rui, Zhou, Yuhao, Xi, Zhiheng, Gui, Tao, Zhang, Qi, Huang, Xuanjing
–arXiv.org Artificial Intelligence
Deep neural networks (DNNs) are notoriously vulnerable to adversarial attacks that place carefully crafted perturbations on normal examples to fool DNNs. To better understand such attacks, a characterization of the features carried by adversarial examples is needed. In this paper, we tackle this challenge by inspecting the subspaces of sample features through spectral analysis. We first empirically show that the features of either clean signals or adversarial perturbations are redundant and span in low-dimensional linear subspaces respectively with minimal overlap, and the classical low-dimensional subspace projection can suppress perturbation features out of the subspace of clean signals. This makes it possible for DNNs to learn a subspace where only features of clean signals exist while those of perturbations are discarded, which can facilitate the distinction of adversarial examples. To prevent the residual perturbations that is inevitable in subspace learning, we propose an independence criterion to disentangle clean signals from perturbations. Experimental results show that the proposed strategy enables the model to inherently suppress adversaries, which not only boosts model robustness but also motivates new directions of effective adversarial defense.
arXiv.org Artificial Intelligence
Mar-24-2024
- Country:
- Africa > Ethiopia (0.04)
- Oceania > Australia
- North America
- United States
- Oregon > Multnomah County
- Portland (0.04)
- Minnesota > Hennepin County
- Minneapolis (0.04)
- Louisiana > Orleans Parish
- New Orleans (0.04)
- Colorado > Denver County
- Denver (0.04)
- California
- San Francisco County > San Francisco (0.14)
- Los Angeles County > Long Beach (0.14)
- San Diego County > San Diego (0.04)
- Oregon > Multnomah County
- Canada
- Ontario > Toronto (0.05)
- Quebec > Montreal (0.04)
- British Columbia > Metro Vancouver Regional District
- Vancouver (0.14)
- Alberta > Census Division No. 15
- Improvement District No. 9 > Banff (0.04)
- United States
- Europe
- Italy (0.04)
- France (0.04)
- Austria (0.04)
- United Kingdom > England
- Cambridgeshire > Cambridge (0.04)
- Ireland > Leinster
- County Dublin > Dublin (0.04)
- Belgium > Brussels-Capital Region
- Brussels (0.04)
- Asia
- Genre:
- Research Report > New Finding (0.48)
- Industry:
- Information Technology > Security & Privacy (0.49)
- Government (0.35)
- Technology: