Revisiting Hilbert-Schmidt Information Bottleneck for Adversarial Robustness
Zifeng Wang, Tong Jian, Aria Masoomi, Stratis Ioannidis, Jennifer G. Dy
摘要
We investigate the HSIC (Hilbert-Schmidt independence criterion) bottleneck as a regularizer for learning an adversarially robust deep neural network classifier. In addition to the usual cross-entropy loss, we add regularization terms for every intermediate layer to ensure that the latent representations retain useful information for output prediction while reducing redundant information. We show that the HSIC bottleneck enhances robustness to adversarial attacks both theoretically and experimentally. In particular, we prove that the HSIC bottleneck regularizer reduces the sensitivity of the classifier to adversarial examples. Our experiments on multiple benchmark datasets and architectures demonstrate that incorporating an HSIC bottleneck regularizer attains competitive natural accuracy and improves adversarial robustness, both with and without adversarial examples during training. Our code and adversarially robust models are publicly available. 2 * Equal contribution.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Graph Bottlenecked Social RecommendationYonghui Yang, Le Wu, Zihan Wang, Zhuangzhuang He 等KDD 2024 · 被引用 34 次
- Automatic Network Pruning via Hilbert-Schmidt Independence Criterion Lasso under Information Bottleneck PrincipleSong Guo, Lei Zhang, Xiawu Zheng, Yan Wang 等ICCV 2023 · 被引用 30 次
- Improving Adversarial Robustness via Information Bottleneck DistillationHuafeng Kuang, Hong Liu, Yongjian Wu, Shin'ichi Satoh 等NeurIPS 2023 · 被引用 27 次
- DualHSIC: HSIC-Bottleneck and Alignment for Continual LearningZifeng Wang, Zheng Zhan, Yifan Gong, Yucai Shao 等ICML 2023 · 被引用 21 次
- Cauchy-Schwarz Divergence Information Bottleneck for RegressionShujian Yu, Xi Yu, Sigurd Løkse, Robert Jenssen 等ICLR 2024 · 被引用 16 次
它引用的顶会 Paper6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey 等ICLR 2020 · 被引用 829 次
- Understanding and Mitigating the Tradeoff between Robustness and AccuracyAditi Raghunathan, Sang Michael Xie, Fanny Yang, John C. Duchi 等ICML 2020 · 被引用 252 次
- The HSIC Bottleneck: Deep Learning without Back-PropagationKurt Wan-Duo Ma, J. P. Lewis, W. Bastiaan KleijnAAAI 2020 · 被引用 180 次
相关 Paper
- Defending Adversarial Examples via DNN Bottleneck ReinforcementWenqing Liu, Miaojing Shi, Teddy Furon, Li LiACM MM 2020 · 被引用 4 次
- H-SPLID: HSIC-based Saliency Preserving Latent Information DecompositionLukas Miklautz, Chengzhi Shi, Andrii Shkabrii, Theodoros-Thirimachos Davarakis 等NeurIPS 2025 · 被引用 2 次
- Towards Robustness of Deep Neural Networks via RegularizationYao Li, Martin Renqiang Min, Thomas C. M. Lee, Wenchao Yu 等ICCV 2021 · 被引用 8 次
- Graph Adversarial Defense via Hilbert-Schmidt Independence Criterion against Influence Maximization AttacksYuxing Guo, Jianqing Liang, Kaixuan Yao, Zhihao Guo 等WWW 2026
- Towards Better Robust Generalization with Shift Consistency RegularizationShufei Zhang, Zhuang Qian, Kaizhu Huang, Qiufeng Wang 等ICML 2021 · 被引用 18 次
