DRFGD: Disentangled Representation-Focused Generative Defense for Attack-Tolerant Cross-Modal Hashing
Zhongqing Yu, Xin Liu, Yiu-ming Cheung, Zhikai Hu, Wentao Fan, Pan Zhou
Abstract
With the widespread deployment of cross-modal retrieval in real-world scenarios, ensuring robustness against adversarial attacks is increasingly critical. Remarkably, deep cross-modal hashing is highly vulnerable to adversarial attacks due to its discrete nature and low-dimensional hash codes, while existing defense methods often fail to suppress perturbations embedded in vulnerable features and lack the capacity to model modality-specific structural differences, resulting in suboptimal adversarial robustness. To address these challenges, we propose a novel Disentangled Representation-Focused Generative Defense (DRFGD) framework for attack-tolerant cross-modal hashing. Without altering the structure of retrieval model, DRFGD defends against adversarial attacks by disentangling input representations into adversarial-robust and adversarial-vulnerable components, by an efficient dual-branch semantic-aware encoder. Guided by such disentangled robust features, an attack-tolerant generative module is seamlessly designed to synthesize semantically aligned and perturbation-resilient examples for robust adversarial training, thereby significantly promoting collaborative defense robustness to attackers. Consequently, the semantically consistent hash codes can be well obtained to enhance adversarial robustness in complex cross-modal attacking scenarios. Extensive experiments on public benchmarks demonstrate that DRFGD substantially improves retrieval robustness under various attacking scenarios, and shows its improved defense performance in comparison with the SOTA works.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f05cc9da-15e6-4810-b653-c6ed68eb6d67Builds on11
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Diffusion Models for Adversarial PurificationWeili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao et al.ICML 2022 · 663 citations
- Deep Graph-neighbor Coherence Preserving Network for Unsupervised Cross-modal HashingJun Yu, Hao Zhou, Yibing Zhan, Dacheng TaoAAAI 2021 · 184 citations
- Towards Defending against Adversarial Examples via Attack-Invariant FeaturesDawei Zhou, Tongliang Liu, Bo Han, Nannan Wang et al.ICML 2021 · 55 citations
- Dual Self-Paced Cross-Modal HashingYuan Sun, Jian Dai, Zhenwen Ren, Yingke Chen et al.AAAI 2024 · 35 citations
Related papers
- Vulnerability vs. Reliability: Disentangled Adversarial Examples for Cross-Modal LearningChao Li, Haoteng Tang, Cheng Deng, Liang Zhan et al.KDD 2020 · 19 citations
- Two-Stage Adversarial Training for Deep Hashing via Representation DistillationFei Zhu, Huashan Chen, Wanqian Zhang, Lin Wang et al.SIGIR 2025 · 2 citations
- Prototype-Supervised Adversarial Network for Targeted Attack of Deep HashingXunguang Wang, Zheng Zhang, Baoyuan Wu, Fumin Shen et al.CVPR 2021
- CgAT: Center-Guided Adversarial Training for Deep Hashing-Based RetrievalXunguang Wang, Yiqun Lin, Xiaomeng LiWWW 2023 · 10 citations
- Spectral-Adaptive Adversarial Hashing for Robust Image RetrievalGang Zhou, Shibiao Xu, Xiaolong Zheng, Daniel Dajun ZengSIGIR 2026
