PAIR: Pre-denosing Augmented Image Retrieval Model for Defending Adversarial Patches
Ziyang Zhou, Pinghui Wang, Zi Liang, Ruofei Zhang, Haitao Bai
摘要
Deep neural networks are widely used in retrieval systems. However, they are notoriously vulnerable to attack. Among the various forms of adversarial attacks, the patch attack is one of the most threatening forms. This type of attack can introduce cognitive biases into the retrieval system by inserting deceptive patches into images. Despite the seriousness of this threat, there are still no well-established solutions in image retrieval systems. In this paper, we propose the Pre-denosing Augmented Image Retrieval (PAIR) model, a new approach designed to protect image retrieval systems against adversarial patch attacks. The core strategy of PAIR is to dynamically and randomly reconstruct entire images based on their semantic content. This purifies well-designed patch attacks while preserving the semantic integrity of the images. Furthermore, we present a novel training strategy that incorporates a semantic discriminator. This discriminator significantly improves PAIR's ability to capture real semantics and reconstruct images. Experiments show that PAIR significantly outperforms existing defense methods. It effectively reduces the success rate of two state-of-the-art patch attack methods to below 5%, achieving a 14% improvement over current leading methods. Moreover, in defending against global perturbation attacks, PAIR also achieves competitive results.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper2
- DRFGD: Disentangled Representation-Focused Generative Defense for Attack-Tolerant Cross-Modal HashingZhongqing Yu, Xin Liu, Yiu-ming Cheung, Zhikai Hu 等AAAI 2026
- Cross-Modal 3D Representation with Multi-View Images and Point CloudsZiyang Zhou, Pinghui Wang, Zi Liang, Haitao Bai 等CVPR 2025
相关 Paper
- PAD: Patch-Agnostic Defense against Adversarial Patch AttacksLihua Jing, Rui Wang, Wenqi Ren, Xin Dong 等CVPR 2024
- PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image ClassifierChong Xiang, Saeed Mahloujifar, Prateek MittalUSENIX Security 2022
- Defending Physical Adversarial Attack on Object Detection via Adversarial Patch-Feature EnergyTaeheon Kim, Youngjoon Yu, Yong Man RoACM MM 2022 · 被引用 19 次
- Delving into Deep Image Prior for Adversarial Defense: A Novel Reconstruction-based Defense FrameworkLi Ding, Yongwei Wang, Xin Ding, Kaiwen Yuan 等ACM MM 2021 · 被引用 7 次
- Jedi: Entropy-Based Localization and Removal of Adversarial PatchesBilel Tarchoun, Anouar Ben Khalifa, Mohamed Ali Mahjoub, Nael B. Abu-Ghazaleh 等CVPR 2023
