AdvFilter: Predictive Perturbation-aware Filtering against Adversarial Attack via Multi-domain Learning
Yihao Huang, Qing Guo, Felix Juefei-Xu, Lei Ma, Weikai Miao, Yang Liu, Geguang Pu
Abstract
High-level representation-guided pixel denoising and adversarial training are independent solutions to enhance the robustness of CNNs against adversarial attacks by pre-processing input data and re-training models, respectively. Most recently, adversarial training techniques have been widely studied and improved while the pixel denoising-based method is getting less attractive. However, it is still questionable whether there exists a more advanced pixel denoising-based method and whether the combination of the two solutions benefits each other. To this end, we first comprehensively investigate two kinds of pixel denoising methods for adversarial robustness enhancement (i.e., existing additive-based and unexplored filtering-based methods) under the loss functions of image-level and semantic-level, respectively, showing that pixel-wise filtering can obtain much higher image quality (e.g., higher PSNR) as well as higher robustness (e.g., higher accuracy on adversarial examples) than existing pixel-wise additive-based method. However, we also observe that the robustness results of the filtering-based method rely on the perturbation amplitude of adversarial examples used for training. To address this problem, we propose predictive perturbation-aware & pixel-wise filtering, where dual-perturbation filtering and an uncertainty-aware fusion module are designed and employed to automatically perceive the perturbation amplitude during the training and testing process. The method is termed as AdvFilter. Moreover, we combine adversarial pixel denoising methods with three adversarial training-based methods, hinting that considering data and models jointly is able to achieve more robust CNNs. The experiments conduct on NeurIPS-2017DEV, SVHN and CIFAR10 datasets and show advantages over enhancing CNNs' robustness, high generalization to different models and noise levels.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Does Few-Shot Learning Suffer from Backdoor Attacks?Xinwei Liu, Xiaojun Jia, Jindong Gu, Yuan Xun et al.AAAI 2024 · 24 citations
- ALA: Naturalness-aware Adversarial Lightness AttackYihao Huang, Liangru Sun, Qing Guo, Felix Juefei-Xu et al.ACM MM 2023 · 15 citations
- Multimodal Unlearnable Examples: Protecting Data against Multimodal Contrastive LearningXinwei Liu, Xiaojun Jia, Yuan Xun, Siyuan Liang et al.ACM MM 2024 · 11 citations
- IRAD: Implicit Representation-driven Image Resampling against Adversarial AttacksYue Cao, Tianlin Li, Xiaofeng Cao, Ivor W. Tsang et al.ICLR 2024 · 4 citations
- Efficient Universal Goal Hijacking with Semantics-guided Prompt OrganizationYihao Huang, Chong Wang, Xiaojun Jia, Qing Guo et al.ACL 2025
Builds on2
Related papers
- A Combination of Noise and Bilateral Filters Achieve Supralinear and Scalable Adversarial Robustness in CNNsNicolas Stalder, Benjamin F Grewe, Matteo Saponati, Pau Vilimelis AceitunoCVPR 2026
- First Line of Defense: A Robust First Layer Mitigates Adversarial AttacksJanani Suresh, Nancy Nayak, Sheetal KalyaniAAAI 2025 · 1 citation
- Phase and Amplitude-aware Prompting for Enhancing Adversarial RobustnessYibo Xu, Dawei Zhou, Decheng Liu, Nannan WangICML 2025
- Phase-aware Adversarial Defense for Improving Adversarial RobustnessDawei Zhou, Nannan Wang, Heng Yang, Xinbo Gao et al.ICML 2023 · 14 citations
- DAT: Improving Adversarial Robustness via Generative Amplitude Mix-up in Frequency DomainFengpeng Li, Kemou Li, Haiwei Wu, Jinyu Tian et al.NeurIPS 2024 · 19 citations
