Can Shape Structure Features Improve Model Robustness under Diverse Adversarial Settings?
Mingjie Sun, Zichao Li, Chaowei Xiao, Haonan Qiu, Bhavya Kailkhura, Mingyan Liu, Bo Li
摘要
Recent studies show that convolutional neural networks (CNNs) are vulnerable under various settings, including adversarial attacks, common corruptions, and backdoor attacks. Motivated by the findings that human visual sys-tem pays more attention to global structure (e.g., shapes) for recognition while CNNs are biased towards local texture features in images, in this work we aim to analyze whether "edge features" could improve the recognition robustness in these scenarios, and if so, to what extent? To answer these questions and systematically evaluate the global structure features, we focus on shape features and pro-pose two edge-enabled pipelines EdgeNetRob and Edge-GANRob, forcing the CNNs to rely more on edge features. Specifically, EdgeNetRob and EdgeGANRob first explicitly extract shape structure features from a given image via an edge detection algorithm. Then EdgeNetRob trains down-stream learning tasks directly on the extracted edge features, while EdgeGANRob reconstructs a new image by refilling the texture information with a trained generative adversarial network (GANs). To reduce the sensitivity of edge detection algorithms to perturbations, we additionally propose a robust edge detection approach Robust Canny based on vanilla Canny. Based on our evaluation, we find that EdgeNetRob can help boost model robustness under different attack scenarios at the cost of the clean model accuracy. EdgeGANRob, on the other hand, is able to improve the clean model accuracy compared to EdgeNetRob while preserving the robustness. This shows that given such edge features, how to leverage them matters for robustness, and it also depends on data properties. Our systematic studies on edge structure features under different settings will shed light on future robust feature exploration and optimization.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- AugMax: Adversarial Composition of Random Augmentations for Robust TrainingHaotao Wang, Chaowei Xiao, Jean Kossaifi, Zhiding Yu 等NeurIPS 2021 · 被引用 153 次
- HybridAugment++: Unified Frequency Spectra Perturbations for Model RobustnessMehmet Kerim Yucel, Ramazan Gokberk Cinbis, Pinar DuyguluICCV 2023 · 被引用 16 次
- Shift from Texture-bias to Shape-bias: Edge Deformation-based Augmentation for Robust Object RecognitionXilin He, Qinliang Lin, Cheng Luo, Weicheng Xie 等ICCV 2023 · 被引用 14 次
- Robo-SGG: Exploiting Layout-Oriented Normalization and Restitution Can Improve Robust Scene Graph GenerationChangsheng Lv, Zijian Fu, Mengshi QiCVPR 2026 · 被引用 4 次
它引用的顶会 Paper6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution GeneralizationDan Hendrycks, Steven Basart, Norman Mu, Saurav Kadavath 等ICCV 2021 · 被引用 2,294 次
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph 等ICLR 2020 · 被引用 1,572 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou 等CCS 2019 · 被引用 626 次
相关 Paper
- Harnessing Edge Information for Improved Robustness in Vision TransformersYanxi Li, Chengbin Du, Chang XuAAAI 2024 · 被引用 7 次
- Does enhanced shape bias improve neural network robustness to common corruptions?Chaithanya Kumar Mummadi, Ranjitha Subramaniam, Robin Hutmacher, Julien Vitay 等ICLR 2021 · 被引用 47 次
- Shape-Biased Domain Generalization via Shock Graph EmbeddingsMaruthi Narayanan, Vickram Rajendran, Benjamin B. KimiaICCV 2021 · 被引用 15 次
- Edges to Shapes to Concepts: Adversarial Augmentation for Robust VisionAditay Tripathi, Rishubh Singh, Anirban Chakraborty, Pradeep ShenoyCVPR 2023
- Informative Dropout for Robust Representation Learning: A Shape-bias PerspectiveBaifeng Shi, Dinghuai Zhang, Qi Dai, Zhanxing Zhu 等ICML 2020 · 被引用 122 次
