CgAT: Center-Guided Adversarial Training for Deep Hashing-Based Retrieval
Xunguang Wang, Yiqun Lin, Xiaomeng Li
Abstract
Deep hashing has been extensively utilized in massive image retrieval because of its efficiency and effectiveness. However, deep hashing models are vulnerable to adversarial examples, making it essential to develop adversarial defense methods for image retrieval. Existing solutions achieved limited defense performance because of using weak adversarial samples for training and lacking discriminative optimization objectives to learn robust features. In this paper, we present a min-max based Center-guided Adversarial Training, namely CgAT, to improve the robustness of deep hashing networks through worst adversarial examples. Our key idea is to formulate a hash code (dubbed center code) as a discriminative semantic representation of the original sample, which can be used to guide the generation of the powerful adversarial example and as an accurate optimization objective for adversarial training. Specifically, we first formulate the center code as a semantically-discriminative representative of the input image content, which preserves the semantic similarity with positive samples and dissimilarity with negative examples. We prove that a mathematical formula can calculate the center code immediately. After obtaining the center codes in each optimization iteration of the deep hashing network, they are adopted to guide the adversarial training process. On the one hand, CgAT generates the worst adversarial examples as augmented data by maximizing the Hamming distance between the hash codes of the adversarial examples and the center codes. On the other hand, CgAT learns to mitigate the effects of adversarial samples by minimizing the Hamming distance to the center codes. Extensive experiments on the benchmark datasets demonstrate the effectiveness of our adversarial training algorithm in defending against adversarial attacks for deep hashing-based retrieval. Compared with the current state-of-the-art defense method, we significantly improve the defense performance by an average of 18.61%, 12.35%, and 11.56% on FLICKR-25K, NUS-WIDE, and MS-COCO, respectively. The code is available at https://github.com/xunguangwang/CgAT .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 19eedb20-ae34-4444-9b27-026cfc6b2c74Cited by top-tier papers1
Ask how each one uses itBuilds on10
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Bag of Tricks for Adversarial TrainingTianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su et al.ICLR 2021 · 298 citations
- One Loss for All: Deep Hashing with a Single Cosine Similarity based Learning ObjectiveJiun Tian Hoe, Kam Woh Ng, Tianyu Zhang, Chee Seng Chan et al.NeurIPS 2021 · 174 citations
- One Loss for Quantization: Deep Hashing with Discrete Wasserstein Distributional MatchingKhoa D. Doan, Peng Yang, Ping LiCVPR 2022 · 46 citations
- Partial-Softmax Loss based Deep HashingRong-Cheng Tu, Xian-Ling Mao, Jia-Nan Guo, Wei Wei et al.WWW 2021 · 43 citations
Related papers
- Two-Stage Adversarial Training for Deep Hashing via Representation DistillationFei Zhu, Huashan Chen, Wanqian Zhang, Lin Wang et al.SIGIR 2025 · 2 citations
- Prototype-Supervised Adversarial Network for Targeted Attack of Deep HashingXunguang Wang, Zheng Zhang, Baoyuan Wu, Fumin Shen et al.CVPR 2021
- Spectral-Adaptive Adversarial Hashing for Robust Image RetrievalGang Zhou, Shibiao Xu, Xiaolong Zheng, Daniel Dajun ZengSIGIR 2026
- DRFGD: Disentangled Representation-Focused Generative Defense for Attack-Tolerant Cross-Modal HashingZhongqing Yu, Xin Liu, Yiu-ming Cheung, Zhikai Hu et al.AAAI 2026
- Precise Target-Oriented Attack against Deep Hashing-based RetrievalWenshuo Zhao, Jingkuan Song, Shengming Yuan, Lianli Gao et al.ACM MM 2023 · 8 citations
