跳到主要导航 跳到搜索 跳到主要内容

An orthogonal classifier for improving the adversarial robustness of neural networks

  • Cong Xu
  • , Xiang Li
  • , Min Yang*
  • *此作品的通讯作者
  • Yantai University

科研成果: 期刊稿件文章同行评审

摘要

Neural networks are susceptible to artificially designed adversarial perturbations. Recent efforts have shown that imposing certain modifications on classification layer can improve the robustness of the neural networks. In this paper, we explicitly construct a dense orthogonal weight matrix whose entries have the same magnitude, thereby leading to a novel robust classifier. The proposed classifier avoids the undesired structural redundancy issue in previous work. Applying this classifier in standard training on clean data is sufficient to ensure the high accuracy and good robustness of the model. Moreover, when extra adversarial samples are used, better robustness can be further obtained with the help of a special worst-case loss. Experimental results show that our method is efficient and competitive to many state-of-the-art defensive approaches. Our code is available at https://github.com/MTandHJ/roboc.

源语言英语
页(从-至)251-262
页数12
期刊Information Sciences
591
DOI
出版状态已出版 - 4月 2022

指纹

探究 'An orthogonal classifier for improving the adversarial robustness of neural networks' 的科研主题。它们共同构成独一无二的指纹。

引用此