RetrievalGuard: Provably Robust 1-Nearest Neighbor Image Retrieval
Yihan Wu, Hongyang Zhang, Heng Huang
摘要
Recent research works have shown that image retrieval models are vulnerable to adversarial attacks, where slightly modified test inputs could lead to problematic retrieval results. In this paper, we aim to design a provably robust image retrieval model which keeps the most important evaluation metric Recall@1 invariant to adversarial perturbation. We propose the first 1-nearest neighbor (NN) image retrieval algorithm, RetrievalGuard, which is provably robust against adversarial perturbations within an ball of calculable radius. The challenge is to design a provably robust algorithm that takes into consideration the 1-NN search and the high-dimensional nature of the embedding space. Algorithmically, given a base retrieval model and a query sample, we build a smoothed retrieval model by carefully analyzing the 1-NN search procedure in the high-dimensional embedding space. We show that the smoothed retrieval model has bounded Lipschitz constant and thus the retrieval score is invariant to adversarial perturbations. Experiments on image retrieval tasks validate the robustness of our RetrievalGuard method.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Faster Adaptive Federated LearningXidong Wu, Feihu Huang, Zhengmian Hu, Heng HuangAAAI 2023 · 被引用 99 次
- A Resilient and Accessible Distribution-Preserving Watermark for Large Language ModelsYihan Wu, Zhengmian Hu, Junfeng Guo, Hongyang Zhang 等ICML 2024 · 被引用 50 次
- Adversarial Weight Perturbation Improves Generalization in Graph Neural NetworksYihan Wu, Aleksandar Bojchevski, Heng HuangAAAI 2023 · 被引用 35 次
- PolicyCleanse: Backdoor Detection and Mitigation for Competitive Reinforcement LearningJunfeng Guo, Ang Li, Lixu Wang, Cong LiuICCV 2023 · 被引用 27 次
- Defending against Data-Free Model Extraction by Distributionally Robust Defensive TrainingZhenyi Wang, Li Shen, Tongliang Liu, Tiehang Duan 等NeurIPS 2023 · 被引用 26 次
它引用的顶会 Paper13
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal 等ICLR 2020 · 被引用 384 次
- A Closer Look at Accuracy vs. RobustnessYao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov 等NeurIPS 2020 · 被引用 336 次
- Revisiting Training Strategies and Generalization Performance in Deep Metric LearningKarsten Roth, Timo Milbich, Samarth Sinha, Prateek Gupta 等ICML 2020 · 被引用 187 次
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong 等ICCV 2019 · 被引用 115 次
相关 Paper
- LipSim: A Provably Robust Perceptual Similarity MetricSara Ghazanfari, Alexandre Araujo, Prashanth Krishnamurthy, Farshad Khorrami 等ICLR 2024 · 被引用 14 次
- Defense Against Adversarial Attacks on No-Reference Image Quality Models with Gradient Norm RegularizationYujia Liu, Chenxi Yang, Dingquan Li, Jianhao Ding 等CVPR 2024 · 被引用 15 次
- Adversarial Attack on Deep Product Quantization Network for Image RetrievalYan Feng, Bin Chen, Tao Dai, Shu-Tao XiaAAAI 2020 · 被引用 33 次
- QAIR: Practical Query-Efficient Black-Box Attacks for Image RetrievalXiaodan Li, Jinfeng Li, Yuefeng Chen, Shaokai Ye 等CVPR 2021
- Learning to Hash Robustly, GuaranteedAlexandr Andoni, Daniel BeagleholeICML 2022 · 被引用 12 次
