paper-with-me

홈 › Papers

Improving Adversarial Robustness via Activation Amplification and Attenuation

2026-06-26 · Taïga Gonçalves, Yongsong Huang, Tomo Miyazaki, Shinichiro Omachi arxiv

The existence of adversarial attacks is often attributed to the presence of non-robust features in neural networks. While prior defenses reduce their impact via pruning, masking, or feature recalibration, we instead propose to jointly learn to amplify and attenuate these signals through a simple activation scaling mechanism. To this end, we introduce Activation Amplification and Attenuation (A3), a lightweight plug-in module that enhances adversarial robustness with minimal modifications of the activations. A3 dynamically rescales the activations using a learnable mask and a scaling factor derived from the original activation magnitudes. The influence of adversarial perturbations can be amplified or attenuated using the same learnable parameters by simply flipping the sign of the scaling operation. The amplified signals serve as negative references to construct novel contrastive and ranking loss functions. Experimental analysis shows that learning to degrade the predictions in amplification mode simultaneously improves adversarial robustness in attenuation mode. Moreover, A3 relies on only a small number of learnable parameters, with most of its behavior being determined by the scaling mechanism rather than additional network capacity. Extensive experiments demonstrate that integrating A3 into different backbones, datasets, and training methods consistently improves adversarial robustness while introducing negligible computational and memory overhead compared to existing plug-in modules. Code is available at: https://github.com/tgoncalv/A3.

📄 PDF Abstract BibTeX arXiv:2606.27784

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial Robustness

Similar Papers 제목 키워드 기반

Removing Adversarial Noise in Class Activation Feature Space

2021-04-19 · ICCV 2021 10 · Dawei Zhou, Nannan Wang, Chunlei Peng, Xinbo Gao 외

Deep neural networks (DNNs) are vulnerable to adversarial noise. Preprocessing based defenses could largely remove adversarial noise by processing inputs. However, they are typically affected by the error amplification e…

Adversarial RobustnessDenoising

Weight Map Layer for Noise and Adversarial Attack Robustness

2019-05-02 · Mohammed Amer, Tomás Maul

Convolutional neural networks (CNNs) are known for their good performance and generalization in vision-related tasks and have become state-of-the-art in both application and research-based domains. However, just like oth…

Adversarial Attack

Detecting Adversarial Data via Provable Adversarial Noise Amplification

2026-05-04 · Furkan Mumcu, Yasin Yilmaz arxiv

The nonuniform and growing impact of adversarial noise across the layers of deep neural networks has been used in the literature, without a formal mathematical justification, to detect adversarial inputs and improve robu…

Adversarial Defense

Inducing Data Amplification Using Auxiliary Datasets in Adversarial Training

2022-09-27 · Saehyung Lee, Hyungyu Lee

Several recent studies have shown that the use of extra in-distribution data can lead to a high level of adversarial robustness. However, there is no guarantee that it will always be possible to obtain sufficient extra d…

Adversarial Robustness

The Gaussian Noise Model in the Presence of Inter-channel Stimulated Raman Scattering

2017-12-31

A Gaussian noise (GN) model is presented that properly accounts for an arbitrary frequency dependent signal power profile along the link. This enables the evaluation of the impact of inter-channel stimulated Raman scatte…