Improving Robustness of Deep-Learning-Based Image Reconstruction
Ankit Raj, Yoram Bresler, Bo Li
摘要
Deep-learning-based methods for different applications have been shown vulnerable to adversarial examples. These examples make deployment of such models in safety-critical tasks questionable. Use of deep neural networks as inverse problem solvers has generated much excitement for medical imaging including CT and MRI, but recently a similar vulnerability has also been demonstrated for these tasks. We show that for such inverse problem solvers, one should analyze and study the effect of adversaries in the measurement-space, instead of the signal-space as in previous work. In this paper, we propose to modify the training strategy of end-to-end deep-learning-based inverse problem solvers to improve robustness. We introduce an auxiliary network to generate adversarial examples, which is used in a min-max formulation to build robust image reconstruction networks. Theoretically, we show for a linear reconstruction scheme the min-max formulation results in a singular-value(s) filter regularized solution, which suppresses the effect of adversarial examples occurring because of ill-conditioning in the measurement matrix. We find that a linear network using the proposed min-max learning scheme indeed converges to the same solution. In addition, for non-linear Compressed Sensing (CS) reconstruction using deep networks, we show significant improvement in robustness using the proposed approach over other methods. We complement the theory by experiments for CS on two different datasets and evaluate the effect of increasing perturbations on trained networks. We find the behavior for ill-conditioned and well-conditioned measurement matrices to be qualitatively different.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- How to Robustify Black-Box ML Models? A Zeroth-Order Optimization PerspectiveYimeng Zhang, Yuguang Yao, Jinghan Jia, Jinfeng Yi 等ICLR 2022 · 被引用 41 次
- Center Smoothing: Certified Robustness for Networks with Structured OutputsAounon Kumar, Tom GoldsteinNeurIPS 2021 · 被引用 23 次
- Reasons for the Superiority of Stochastic Estimators over Deterministic Ones: Robustness, Consistency and Perceptual QualityGuy Ohayon, Theo Joseph Adrai, Michael Elad, Tomer MichaeliICML 2023 · 被引用 18 次
- Learning Provably Robust Estimators for Inverse Problems via JitteringAnselm Krainovic, Mahdi Soltanolkotabi, Reinhard HeckelNeurIPS 2023 · 被引用 10 次
- How many measurements are enough? Bayesian recovery in inverse problems with general distributionsBen Adcock, Zi Yuan (Nick) HuangNeurIPS 2025 · 被引用 2 次
它引用的顶会 Paper4
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- Adversarial Defense via Learning to Generate Diverse AttacksYunseok Jang, Tianchen Zhao, Seunghoon Hong, Honglak LeeICCV 2019 · 被引用 88 次
- Evaluating Robustness of Deep Image Super-Resolution Against Adversarial AttacksJun-Ho Choi, Huan Zhang, Jun-Hyuk Kim, Cho-Jui Hsieh 等ICCV 2019 · 被引用 82 次
- GAN-Based Projector for Faster Recovery With Convergence Guarantees in Linear Inverse ProblemsAnkit Raj, Yuqi Li, Yoram BreslerICCV 2019 · 被引用 61 次
相关 Paper
- Measuring Robustness in Deep Learning Based Compressive SensingMohammad Zalbagi Darestani, Akshay S. Chaudhari, Reinhard HeckelICML 2021 · 被引用 94 次
- NPN: Non-Linear Projections of the Null-Space for Imaging Inverse ProblemsRoman Jacome, Romario Gualdrón-Hurtado, León Suárez-Rodríguez, Henry ArguelloNeurIPS 2025 · 被引用 4 次
- Training-Free Adversarial Robustness in Computational MRIMahdi Saberi, Chi Zhang, Mehmet AkcakayaICML 2026 · 被引用 2 次
- Convex Regularization behind Neural ReconstructionArda Sahiner, Morteza Mardani, Batu Ozturkler, Mert Pilanci 等ICLR 2021 · 被引用 25 次
- Equivariant Imaging: Learning Beyond the Range SpaceDongdong Chen, Julián Tachella, Mike E. DaviesICCV 2021 · 被引用 139 次
