浙江大学学报(工学版)2024,Vol.58Issue(11) :2230-2238.DOI:10.3785/j.issn.1008-973X.2024.11.004

基于离散余弦变换的快速对抗训练方法

Fast adversarial training method based on discrete cosine transform

王晓淼 张玉金 张涛 田瑾 吴飞
浙江大学学报(工学版)2024,Vol.58Issue(11) :2230-2238.DOI:10.3785/j.issn.1008-973X.2024.11.004

基于离散余弦变换的快速对抗训练方法

Fast adversarial training method based on discrete cosine transform

王晓淼 1张玉金 1张涛 2田瑾 1吴飞1
扫码查看

作者信息

  • 1. 上海工程技术大学电子电气工程学院,上海 201620
  • 2. 常熟理工学院计算机科学与工程学院,江苏常熟 215500
  • 折叠

摘要

为了提升深度神经网络的鲁棒性,从频域的角度提出基于离散余弦变换(DCT)的快速对抗训练方法.引入对抗初始化生成模块,根据系统的鲁棒性自适应地生成初始化信息,可以更精准地捕捉到图像特征,有效避免灾难性过拟合.对样本进行随机谱变换,将样本从空间域变换至频谱域,通过控制频谱显著性提高模型的迁移与泛化能力.在CIFAR-10与CIFAR-100数据集上验证提出方法的有效性.实验结果表明,在以ResNet18为目标网络,面对PGD-10攻击时,本文方法在CIFAR-10上的鲁棒精度较现有方法提升了2%~9%,在CIFAR-100上提升了1%~9%.在面对PGD-20、PGD-50、C&W等其他攻击以及架构更复杂的模型时,均取得了类似的效果.提出方法在避免灾难性过拟合现象的同时,有效提高了系统的鲁棒性.

Abstract

A fast adversarial training method based on discrete cosine transform (DCT) was proposed from the perspective of the frequency domain in order to enhance the robustness of deep neural network. An adversarial initialization generation module was introduced,which adaptively generated initialization information based on the system's robustness,allowing for more accurate capture of image features and effectively avoiding catastrophic overfitting. Random spectral transformations were applied to the samples,transforming them from the spatial domain to the frequency domain,which improved the model's transferability and generalization ability by controlling spectral saliency. The effectiveness of the proposed method was validated on the CIFAR-10 and CIFAR-100 datasets. The experimental results show that the robust accuracy of the proposed method on CIFAR-10 improved by 2% to 9% compared to existing methods,and improved by 1% to 9% on CIFAR-100 by using ResNet18 as the target network and facing PGD-10 attacks. Similar effects were achieved when facing PGD-20,PGD-50,C&W and other attacks,as well as when applied to more complex model architectures. The proposed method not only avoids catastrophic overfitting but also effectively enhances system robustness.

关键词

对抗样本/快速对抗训练/离散余弦变换(DCT)/鲁棒性/样本初始化

Key words

adversarial example/fast adversarial training/discrete cosine transform (DCT)/robustness/example initialization

引用本文复制引用

出版年

2024
浙江大学学报(工学版)
浙江大学

浙江大学学报(工学版)

CSTPCDCSCD北大核心
影响因子:0.625
ISSN:1008-973X
段落导航相关论文