Appearance and Structure Aware Robust Deep Visual Graph Matching: Attack, Defense and Beyond
Qibing Ren, Qingquan Bao, Runzhong Wang, Junchi Yan
Abstract
Despite the recent breakthrough of high accuracy deep graph matching (GM) over visual images, the robustness of deep GM models is rarely studied which yet has been revealed an important issue in modern deep nets, ranging from image recognition to graph learning tasks. We first show that an adversarial attack on keypoint localities and the hidden graphs can cause significant accuracy drop to deep GM models. Accordingly, we propose our defense strategy, namely Appearance and Structure Aware Robust Graph Matching (ASAR-GM). Specifically, orthogonal to de facto adversarial training (AT), we devise the Appearance Aware Regularizer (AAR) on those appearance-similar keypoints between graphs that are likely to confuse. Experimental results show that our ASAR-GM achieves better robustness compared to AT. Moreover, our locality attack can serve as a data augmentation technique, which boosts the state-of-the-art GM models even on the clean test dataset. Code is available at https://github.com/Thinklab-SJTU/RobustMatch.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1a1aec2b-3f7d-4998-b599-0bbce8bc2577Cited by top-tier papers4
- Graph Matching with Bi-level Noisy CorrespondenceYijie Lin, Mouxing Yang, Jun Yu, Peng Hu et al.ICCV 2023 · 45 citations
- Rethinking and Improving Robustness of Convolutional Neural Networks: a Shapley Value-based Approach in Frequency DomainYiting Chen, Qibing Ren, Junchi YanNeurIPS 2022 · 36 citations
- Improving Graph Matching with Positional Reconstruction Encoder-Decoder NetworkYixiao Zhou, Ruiqi Jia, Hongxiang Lin, Hefeng Quan et al.NeurIPS 2023 · 7 citations
- Effective Federated Graph MatchingYang Zhou, Zijie Zhang, Zeru Zhang, Lingjuan Lyu et al.ICML 2024 · 1 citation
Builds on21
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Attacks Which Do Not Kill Training Make Adversarial Learning StrongerJingfeng Zhang, Xilie Xu, Bo Han, Gang Niu et al.ICML 2020 · 452 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
- Learning Combinatorial Embedding Networks for Deep Graph MatchingRunzhong Wang, Junchi Yan, Xiaokang YangICCV 2019 · 268 citations
- Deep Graph Matching ConsensusMatthias Fey, Jan Eric Lenssen, Christopher Morris, Jonathan Masci et al.ICLR 2020 · 227 citations
Related papers
- Certified Robustness on Visual Graph Matching via Searching Optimal Smoothing RangeHuaqing Shao, Lanjun Wang, Yongwei Wang, Qibing Ren et al.KDD 2024
- GAMnet: Robust Feature Matching via Graph Adversarial-Matching NetworkBo Jiang, Pengfei Sun, Ziyan Zhang, Jin Tang et al.ACM MM 2021 · 8 citations
- Revocable Deep Reinforcement Learning with Affinity Regularization for Outlier-Robust Graph MatchingChang Liu, Zetian Jiang, Runzhong Wang, Lingxiao Huang et al.ICLR 2023 · 2 citations
- Adversarial Attacks on Deep Graph MatchingZijie Zhang, Zeru Zhang, Yang Zhou, Yelong Shen et al.NeurIPS 2020 · 42 citations
- Integrated Defense for Resilient Graph MatchingJiaxiang Ren, Zijie Zhang, Jiayin Jin, Xin Zhao et al.ICML 2021 · 15 citations
