Enhancing Adversarial Defense by k-Winners-Take-All
Chang Xiao, Peilin Zhong, Changxi Zheng
Abstract
We propose a simple change to existing neural network structures for better defending against gradient-based adversarial attacks. Instead of using popular activation functions (such as ReLU), we advocate the use of k-Winners-Take-All (k-WTA) activation, a C0 discontinuous function that purposely invalidates the neural network model's gradient at densely distributed input data points. The proposed k-WTA activation can be readily used in nearly all existing networks and training methods with no significant overhead. Our proposal is theoretically rationalized. We analyze why the discontinuities in k-WTA networks can largely prevent gradient-based search of adversarial examples and why they at the same time remain innocuous to the network training. This understanding is also empirically backed. We test k-WTA activation on various network structures optimized by a training method, be it adversarial training or not. In all cases, the robustness of k-WTA networks outperforms that of traditional networks under white-box attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext def68a02-5f29-481d-966d-afc4d7e68c44Cited by top-tier papers27
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Adversarial Purification with Score-based Generative ModelsJongmin Yoon, Sung Ju Hwang, Juho LeeICML 2021 · 200 citations
- Learnable Boundary Guided Adversarial TrainingJiequan Cui, Shu Liu, Liwei Wang, Jiaya JiaICCV 2021 · 152 citations
- Meta Gradient Adversarial AttackZheng Yuan, Jie Zhang, Yunpei Jia, Chuanqi Tan et al.ICCV 2021 · 95 citations
- Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image ClassifiersFrancesco Croce, Matthias HeinICML 2021 · 68 citations
Builds on2
Related papers
- Discrete Adversarial Attack to Models of CodeFengjuan Gao, Yu Wang, Ke WangPLDI 2023 · 23 citations
- Low Curvature Activations Reduce Overfitting in Adversarial TrainingVasu Singla, Sahil Singla, Soheil Feizi, David JacobsICCV 2021 · 49 citations
- Detecting Adversarial Samples Using Influence Functions and Nearest NeighborsGilad Cohen, Guillermo Sapiro, Raja GiryesCVPR 2020
- One Man's Trash Is Another Man's Treasure: Resisting Adversarial Examples by Adversarial ExamplesChang Xiao, Changxi ZhengCVPR 2020
- TRNAS: A Training-Free Robust Neural Architecture SearchYeming Yang, Qingling Zhu, Jianping Luo, Ka-Chun Wong et al.ICCV 2025 · 1 citation
