Feature Separation and Recalibration for Adversarial Robustness
Woo Jae Kim, Yoonki Cho, Junsik Jung, Sung-Eui Yoon
Abstract
Deep neural networks are susceptible to adversarial attacks due to the accumulation of perturbations in the feature level, and numerous works have boosted model robustness by deactivating the non-robust feature activations that cause model mispredictions. However, we claim that these malicious activations still contain discriminative cues and that with recalibration, they can capture additional useful information for correct model predictions. To this end, we propose a novel, easy-to-plugin approach named Feature Separation and Recalibration (FSR) that recalibrates the malicious, non-robust activations for more robust feature maps through Separation and Recalibration. The Separation part disentangles the input feature map into the robust feature with activations that help the model make correct predictions and the non-robust feature with activations that are responsible for model mispredictions upon adversarial attack. The Recalibration part then adjusts the non-robust activations to restore the potentially useful cues for model predictions. Extensive experiments verify the superiority of FSR compared to traditional deactivation techniques and demonstrate that it improves the robustness of existing adversarial training methods by up to 8.57% with small computational overhead. Codes are available at https://github.com/wkim97/FSR .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- Distilling Out-of-Distribution Robustness from Vision-Language Foundation ModelsAndy Zhou, Jindong Wang, Yu-Xiong Wang, Haohan WangNeurIPS 2023 · 14 citations
- Fixed Non-negative Orthogonal Classifier: Inducing Zero-mean Neural Collapse with Feature Dimension SeparationHoyong Kim, Kangil KimICLR 2024 · 7 citations
- Uncertainty-Aware Gradient Stabilization for Small Object DetectionHuixin Sun, Yanjing Li, Linlin Yang, Xianbin Cao et al.ICCV 2025 · 6 citations
- Mitigating Feature Gap for Adversarial Robustness by Feature DisentanglementNuoyan Zhou, Dawei Zhou, Decheng Liu, Nannan Wang et al.AAAI 2025 · 3 citations
- Towards Adversarial Robustness via Debiased High-Confidence Logit AlignmentKejia Zhang, Juanjuan Weng, Shaozi Li, Zhiming LuoICCV 2025
Builds on23
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
Related papers
- Adversarial Feature DesensitizationPouya Bashivan, Reza Bayat, Adam Ibrahim, Kartik Ahuja et al.NeurIPS 2021 · 22 citations
- Improving Adversarial Robustness via Channel-wise Activation SuppressingYang Bai, Yuyuan Zeng, Yong Jiang, Shu-Tao Xia et al.ICLR 2021 · 59 citations
- Distilling Robust and Non-Robust Features in Adversarial Examples by Information BottleneckJunho Kim, Byung-Kwan Lee, Yong Man RoNeurIPS 2021 · 57 citations
- DANCE: Enhancing saliency maps using decoysYang Young Lu, Wenbo Guo, Xinyu Xing, William Stafford NobleICML 2021 · 14 citations
- Improving Calibration through the Relationship with Adversarial RobustnessYao Qin, Xuezhi Wang, Alex Beutel, Ed H. ChiNeurIPS 2021 · 32 citations
