Dynamic Divide-and-Conquer Adversarial Training for Robust Semantic Segmentation
Xiaogang Xu, Hengshuang Zhao, Jiaya Jia
摘要
Adversarial training is promising for improving robustness of deep neural networks towards adversarial perturbations, especially on the classification task. The effect of this type of training on semantic segmentation, contrarily, just commences. We make the initial attempt to explore the defense strategy on semantic segmentation by formulating a general adversarial training procedure that can per-form decently on both adversarial and clean samples. We propose a dynamic divide-and-conquer adversarial training (DDC-AT) strategy to enhance the defense effect, by set-ting additional branches in the target model during training, and dealing with pixels with diverse properties to-wards adversarial perturbation. Our dynamical division mechanism divides pixels into multiple branches automatically. Note all these additional branches can be abandoned during inference and thus leave no extra parameter and computation cost. Extensive experiments with various segmentation models are conducted on PASCAL VOC 2012 and Cityscapes datasets, in which DDC-AT yields satisfying performance under both white- and black-box at-tack. The code is available at https://github.com/dvlab-research/Robust-Semantic-Segmentation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Boosting Adversarial Training with Hypersphere EmbeddingTianyu Pang, Xiao Yang, Yinpeng Dong, Taufik Xu 等NeurIPS 2020 · 被引用 170 次
- PAIF: Perception-Aware Infrared-Visible Image Fusion for Attack-Tolerant Semantic SegmentationZhu Liu, Jinyuan Liu, Benzhuang Zhang, Long Ma 等ACM MM 2023 · 被引用 47 次
- CosPGD: an efficient white-box adversarial attack for pixel-wise prediction tasksShashank Agnihotri, Steffen Jung, Margret KeuperICML 2024 · 被引用 35 次
- Collective Robustness Certificates: Exploiting Interdependence in Graph Neural NetworksJan Schuchardt, Aleksandar Bojchevski, Johannes Klicpera, Stephan GünnemannICLR 2021 · 被引用 29 次
- UnSeg: One Universal Unlearnable Example Generator is Enough against All Image SegmentationYe Sun, Hao Zhang, Tiehua Zhang, Xingjun Ma 等NeurIPS 2024 · 被引用 18 次
它引用的顶会 Paper3
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Bilateral Adversarial Training: Towards Fast Training of More Robust Models Against Adversarial AttacksJianyu Wang, Haichao ZhangICCV 2019 · 被引用 120 次
- Boosting the Transferability of Adversarial Samples via AttentionWeibin Wu, Yuxin Su, Xixian Chen, Shenglin Zhao 等CVPR 2020
相关 Paper
- Defending Against Universal Perturbations With Shared Adversarial TrainingChaithanya Kumar Mummadi, Thomas Brox, Jan Hendrik MetzenICCV 2019 · 被引用 61 次
- Robustness and Generalization via Generative Adversarial TrainingOmid Poursaeed, Tianxing Jiang, Harry Yang, Serge J. Belongie 等ICCV 2021 · 被引用 35 次
- Adversarial Style Augmentation for Domain Generalized Urban-Scene SegmentationZhun Zhong, Yuyang Zhao, Gim Hee Lee, Nicu SebeNeurIPS 2022 · 被引用 130 次
- Efficient and Effective Augmentation Strategy for Adversarial TrainingSravanti Addepalli, Samyak Jain, Venkatesh Babu R.NeurIPS 2022 · 被引用 77 次
- Benchmarking the Robustness of Semantic Segmentation ModelsChristoph Kamann, Carsten RotherCVPR 2020
