Improving VAEs' Robustness to Adversarial Attack
Matthew Willetts, Alexander Camuto, Tom Rainforth, Stephen J. Roberts, Christopher C. Holmes
Abstract
Variational autoencoders (VAEs) have recently been shown to be vulnerable to adversarial attacks, wherein they are fooled into reconstructing a chosen target image. However, how to defend against such attacks remains an open problem. We make significant advances in addressing this issue by introducing methods for producing adversarially robust VAEs. Namely, we first demonstrate that methods proposed to obtain disentangled latent representations produce VAEs that are more robust to these attacks. However, this robustness comes at the cost of reducing the quality of the reconstructions. We ameliorate this by applying disentangling methods to hierarchical VAEs. The resulting models produce high-fidelity autoencoders that are also adversarially robust. We confirm their capabilities on several different datasets and with current state-of-the-art VAE adversarial attacks, and also show that they increase the robustness of downstream tasks to attack.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8dc9884d-e539-479d-92cd-5e5c15cdc12fCited by top-tier papers7
- Semi-supervised Semantics-guided Adversarial Training for Robust Trajectory PredictionRuochen Jiao, Xiangguo Liu, Takami Sato, Qi Alfred Chen et al.ICCV 2023 · 26 citations
- Adversarial robustness of amortized Bayesian inferenceManuel Glöckler, Michael Deistler, Jakob H. MackeICML 2023 · 23 citations
- Alleviating Adversarial Attacks on Variational Autoencoders with MCMCAnna Kuzina, Max Welling, Jakub M. TomczakNeurIPS 2022 · 16 citations
- PointCA: Evaluating the Robustness of 3D Point Cloud Completion Models against Adversarial ExamplesShengshan Hu, Junwei Zhang, Wei Liu, Junhui Hou et al.AAAI 2023 · 14 citations
- Adversarial Purification with the Manifold HypothesisZhaoyuan Yang, Zhiwei Xu, Jing Zhang, Richard I. Hartley et al.AAAI 2024 · 12 citations
Related papers
- Class-Disentanglement and Applications in Adversarial Detection and DefenseKaiwen Yang, Tianyi Zhou, Yonggang Zhang, Xinmei Tian et al.NeurIPS 2021 · 49 citations
- The Autoencoding Variational AutoencoderA. Taylan Cemgil, Sumedh Ghaisas, Krishnamurthy Dvijotham, Sven Gowal et al.NeurIPS 2020 · 81 citations
- The role of Disentanglement in GeneralisationMilton Llera Montero, Casimir J. H. Ludwig, Rui Ponte Costa, Gaurav Malhotra et al.ICLR 2021 · 97 citations
- Trading off Image Quality for Robustness is not Necessary with Regularized Deterministic AutoencodersAmrutha Saseendran, Kathrin Skubch, Stefan Falkner, Margret KeuperNeurIPS 2022
- Robustness and Generalization via Generative Adversarial TrainingOmid Poursaeed, Tianxing Jiang, Harry Yang, Serge J. Belongie et al.ICCV 2021 · 35 citations
