paper-with-me

홈 › Papers

Feature Statistics with Uncertainty Help Adversarial Robustness

2025-03-26 · Ran Wang, Xinlei Zhou, Rihao Li, Meng Hu, Wenhui Wu, Yuheng Jia

Despite the remarkable success of deep neural networks (DNNs), the security threat of adversarial attacks poses a significant challenge to the reliability of DNNs. By introducing randomness into different parts of DNNs, stochastic methods can enable the model to learn some uncertainty, thereby improving model robustness efficiently. In this paper, we theoretically discover a universal phenomenon that adversarial attacks will shift the distributions of feature statistics. Motivated by this theoretical finding, we propose a robustness enhancement module called Feature Statistics with Uncertainty (FSU). It resamples channel-wise feature means and standard deviations of examples from multivariate Gaussian distributions, which helps to reconstruct the attacked examples and calibrate the shifted distributions. The calibration recovers some domain characteristics of the data for classification, thereby mitigating the influence of perturbations and weakening the ability of attacks to deceive models. The proposed FSU module has universal applicability in training, attacking, predicting and fine-tuning, demonstrating impressive robustness enhancement ability at trivial additional time cost. For example, against powerful optimization-based CW attacks, by incorporating FSU into attacking and predicting phases, it endows many collapsed state-of-the-art models with 50%-80% robust accuracy on CIFAR10, CIFAR100 and SVHN.

📄 PDF Abstract BibTeX arXiv:2503.20583

Code (1)

techtrekkerz/fsu 공식 구현 pytorch

Tasks

Adversarial Robustness

Similar Papers 제목 키워드 기반

The Many Faces of Adversarial Risk

2022-01-22 · NeurIPS 2021 12 · Muni Sreenivas Pydi, Varun Jog

Adversarial risk quantifies the performance of classifiers on adversarially perturbed data. Numerous definitions of adversarial risk -- not all mathematically rigorous and differing subtly in the details -- have appeared…

Adversarial Robustness

USAD: Uncertainty-aware Statistical Adversarial Detection

2026-06-26 · Zhijian Zhou, Xunye Tian, Jiacheng Zhang, Zesheng Ye 외 arxiv

Statistical adversarial detection (SAD) treats detection as a two-sample test. Given a reference set of clean examples (CEs) and a batch of queries, potentially containing an unknown mixture of CEs and adversarial exampl…

Integrating uncertainty quantification into randomized smoothing based robustness guarantees

2024-10-27 · Sina Däubener, Kira Maag, David Krueger, Asja Fischer

Deep neural networks have proven to be extremely powerful, however, they are also vulnerable to adversarial attacks which can cause hazardous incorrect predictions in safety-critical applications. Certified robustness vi…

Out-of-Distribution DetectionUncertainty Quantification

AGAIN: Adversarial Training With Attribution Span Enlargement and Hybrid Feature Fusion

2023-01-01 · CVPR 2023 1 · Shenglin Yin, Kelu Yao, Sheng Shi, Yangzhou Du 외

The deep neural networks (DNNs) trained by adversarial training (AT) usually suffered from significant robust generalization gap, i.e., DNNs achieve high training robustness but low test robustness. In this paper, we…

Diversity

On the Adversarial Robustness of Vision Transformers

2021-03-29 · Rulin Shao, Zhouxing Shi, JinFeng Yi, Pin-Yu Chen 외

Following the success in advancing natural language processing and understanding, transformers are expected to bring revolutionary changes to computer vision. This work provides a comprehensive study on the robustness of…

Adversarial Robustness