Two-Stage Adversarial Training for Deep Hashing via Representation Distillation
Fei Zhu, Huashan Chen, Wanqian Zhang, Lin Wang, Zheng Lin, Bo Li
摘要
In recent years, the study on defending deep hashing models against adversarial attacks has garnered increasing attention. Among them, adversarial training is an effective method to train robust deep hashing models. Existing adversarial training methods for deep hashing simultaneously optimize original deep hashing loss and proposed adversarial training loss to train a robust model. However, we argue that directly using the original deep hashing loss will guide the model to learn excessive non-robust patterns from clean examples when extracting discriminative semantic information, thereby limiting model robustness. To tackle this, we propose a novel Clean model Representation Distillation based Adversarial Training (CRDAT) method, which enables the robust model to learn both discriminative semantic information and robust patterns by separating these two losses into two stages, i.e., standard training stage of a clean teacher model and adversarial training stage of a robust student model. Specifically, we propose a novel representation distillation based adversarial training loss, which distills the representations of the teacher model on clean examples at both the hash code level and feature level to guide the student model's learning on adversarial examples. Extensive experiments on multiple datasets and deep hashing methods demonstrate that our CRDAT method can greatly improve model robustness and achieve state-of-the-art defense performance.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- CgAT: Center-Guided Adversarial Training for Deep Hashing-Based RetrievalXunguang Wang, Yiqun Lin, Xiaomeng LiWWW 2023 · 被引用 10 次
- DRFGD: Disentangled Representation-Focused Generative Defense for Attack-Tolerant Cross-Modal HashingZhongqing Yu, Xin Liu, Yiu-ming Cheung, Zhikai Hu 等AAAI 2026
- Spectral-Adaptive Adversarial Hashing for Robust Image RetrievalGang Zhou, Shibiao Xu, Xiaolong Zheng, Daniel Dajun ZengSIGIR 2026
- Prototype-Supervised Adversarial Network for Targeted Attack of Deep HashingXunguang Wang, Zheng Zhang, Baoyuan Wu, Fumin Shen 等CVPR 2021
- Vulnerability vs. Reliability: Disentangled Adversarial Examples for Cross-Modal LearningChao Li, Haoteng Tang, Cheng Deng, Liang Zhan 等KDD 2020 · 被引用 19 次
