Exploiting Joint Robustness to Adversarial Perturbations
Ali Dabouei, Sobhan Soleymani, Fariborz Taherkhani, Jeremy M. Dawson, Nasser M. Nasrabadi
Abstract
Recently, ensemble models have demonstrated empirical capabilities to alleviate the adversarial vulnerability. In this paper, we exploit first-order interactions within ensembles to formalize a reliable and practical defense. We introduce a scenario of interactions that certifiably improves the robustness according to the size of the ensemble, the diversity of the gradient directions, and the balance of the member's contribution to the robustness. We present a joint gradient phase and magnitude regularization (GPMR) as a vigorous approach to impose the desired scenario of interactions among members of the ensemble. Through extensive experiments, including gradient-based and gradient-free evaluations on several datasets and network architectures, we validate the practical effectiveness of the proposed approach compared to the previous methods. Furthermore, we demonstrate that GPMR is orthogonal to other defense strategies developed for single classifiers and their combination can further improve the robustness of ensembles.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 35c70af9-d217-4c51-951e-6d37bf914b1bCited by top-tier papers4
- DICE: Diversity in Deep Ensembles via Conditional Redundancy Adversarial EstimationAlexandre Ramé, Matthieu CordICLR 2021 · 60 citations
- On the Role of Randomization in Adversarially Robust ClassificationLucas Gnecco Heredia, Muni Sreenivas Pydi, Laurent Meunier, Benjamin Négrevergne et al.NeurIPS 2023 · 7 citations
- How Sampling Impacts the Robustness of Stochastic Neural NetworksSina Däubener, Asja FischerNeurIPS 2022 · 1 citation
- On the Diversity of Adversarial Ensemble LearningJun-Qi Guo, Meng-Zhang Qian, Wei Gao, Zhi-Hua ZhouICML 2025
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
Related papers
- On the Certified Robustness for Ensemble Models and BeyondZhuolin Yang, Linyi Li, Xiaojun Xu, Bhavya Kailkhura et al.ICLR 2022 · 57 citations
- Understanding and Improving Ensemble Adversarial DefenseYian Deng, Tingting MuNeurIPS 2023 · 37 citations
- Improving Adversarial Robustness via Guided Complement EntropyHao-Yun Chen, Jhao-Hong Liang, Shih-Chieh Chang, Jia-Yu Pan et al.ICCV 2019 · 51 citations
- Adversarial Defence by Diversified Simultaneous Training of Deep EnsemblesBo Huang, Zhiwei Ke, Yi Wang, Wei Wang et al.AAAI 2021 · 20 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
