LOGICDEF: An Interpretable Defense Framework against Adversarial Examples via Inductive Scene Graph Reasoning
Yuan Yang, James Clayton Kerce, Faramarz Fekri
Abstract
Deep vision models have provided new capability across a spectrum of applications in transportation, manufacturing, agriculture, commerce, and security. However, recent studies have demonstrated that these models are vulnerable to adversarial attack, exposing a risk-of-use in critical applications where untrusted parties have access to the data environment or even directly to the sensor inputs. Existing adversarial defense methods are either limited to specific types of attacks or are too complex to be applied to practical vision models. More importantly, these methods rely on techniques that are not interpretable to humans. In this work, we argue that an effective defense should produce an explanation as to why the system is attacked, and by using a representation that is easily readable by a human user, e.g. a logic formalism. To this end, we propose logic adversarial defense (LogicDef), a defense framework that utilizes the scene graph of the image to provide a contextual structure for detecting and explaining object classification. Our framework first mines inductive logic rules from the extracted scene graph, and then uses these rules to construct a defense model that alerts the user when the vision model violates the consistency rules. The defense model is interpretable and its robustness is further enhanced by incorporating existing relational commonsense knowledge from projects such as ConceptNet. In order to handle the hierarchical nature of such relational reasoning, we use a curriculum learning approach based on object taxonomy, yielding additional improvements to training and performance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3a345dc1-5e74-41fa-9a94-a507257c2e92Cited by top-tier papers1
Ask how each one uses itBuilds on3
- Certified Defenses for Adversarial PatchesPing-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu et al.ICLR 2020 · 194 citations
- Efficient Probabilistic Logic Reasoning with Graph Neural NetworksYuyu Zhang, Xinshi Chen, Yuan Yang, Arun Ramamurthy et al.ICLR 2020 · 119 citations
- Learn to Explain Efficiently via Neural Logic Inductive LearningYuan Yang, Le SongICLR 2020 · 83 citations
Related papers
- PhySense: Defending Physically Realizable Attacks for Autonomous Systems via Consistency ReasoningZhiyuan Yu, Ao Li, Ruoyao Wen, Yijia Chen et al.CCS 2024 · 4 citations
- Knowledge Enhanced Machine Learning Pipeline against Diverse Adversarial AttacksNezihe Merve Gürel, Xiangyu Qi, Luka Rimanic, Ce Zhang et al.ICML 2021 · 51 citations
- Adversarial Attacks are Reversible with Natural SupervisionChengzhi Mao, Mia Chiquier, Hao Wang, Junfeng Yang et al.ICCV 2021 · 66 citations
- Exploiting Multi-Object Relationships for Detecting Adversarial Attacks in Complex ScenesMingjun Yin, Shasha Li, Zikui Cai, Chengyu Song et al.ICCV 2021 · 25 citations
- Value at Adversarial Risk: A Graph Defense Strategy against Cost-Aware AttacksJunlong Liao, Wenda Fu, Cong Wang, Zhongyu Wei et al.AAAI 2024 · 5 citations
