Two-Stage Adversarial Training for Deep Hashing via Representation Distillation
Fei Zhu, Huashan Chen, Wanqian Zhang, Lin Wang, Zheng Lin, Bo Li
Abstract
In recent years, the study on defending deep hashing models against adversarial attacks has garnered increasing attention. Among them, adversarial training is an effective method to train robust deep hashing models. Existing adversarial training methods for deep hashing simultaneously optimize original deep hashing loss and proposed adversarial training loss to train a robust model. However, we argue that directly using the original deep hashing loss will guide the model to learn excessive non-robust patterns from clean examples when extracting discriminative semantic information, thereby limiting model robustness. To tackle this, we propose a novel Clean model Representation Distillation based Adversarial Training (CRDAT) method, which enables the robust model to learn both discriminative semantic information and robust patterns by separating these two losses into two stages, i.e., standard training stage of a clean teacher model and adversarial training stage of a robust student model. Specifically, we propose a novel representation distillation based adversarial training loss, which distills the representations of the teacher model on clean examples at both the hash code level and feature level to guide the student model's learning on adversarial examples. Extensive experiments on multiple datasets and deep hashing methods demonstrate that our CRDAT method can greatly improve model robustness and achieve state-of-the-art defense performance.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b8fc3cf3-fd35-4f29-a18a-0462501235cbRelated papers
- CgAT: Center-Guided Adversarial Training for Deep Hashing-Based RetrievalXunguang Wang, Yiqun Lin, Xiaomeng LiWWW 2023 · 10 citations
- DRFGD: Disentangled Representation-Focused Generative Defense for Attack-Tolerant Cross-Modal HashingZhongqing Yu, Xin Liu, Yiu-ming Cheung, Zhikai Hu et al.AAAI 2026
- Spectral-Adaptive Adversarial Hashing for Robust Image RetrievalGang Zhou, Shibiao Xu, Xiaolong Zheng, Daniel Dajun ZengSIGIR 2026
- Prototype-Supervised Adversarial Network for Targeted Attack of Deep HashingXunguang Wang, Zheng Zhang, Baoyuan Wu, Fumin Shen et al.CVPR 2021
- Vulnerability vs. Reliability: Disentangled Adversarial Examples for Cross-Modal LearningChao Li, Haoteng Tang, Cheng Deng, Liang Zhan et al.KDD 2020 · 19 citations
