ICASSP 2022accepted0 citations

Defending Against Universal Attack Via Curvature-Aware Category Adversarial Training

Peilun Du, Xiaolong Zheng, Liang Liu, Huadong Ma

Abstract

Adversarial training can defend against universal adversarial perturbation (UAP) by injecting corresponding adversarial samples during training. However, adversarial samples used by existing methods, such as UAP, inevitably include excessive perturbations related to other categories due to its inherent goal of universality. Training with them will cause more erroneous predictions with larger local positive curvature. In this paper, we propose a curvature-aware category adversarial training method to avoid excessive perturbations. We introduce the category-oriented adversarial masks that are synthesized with class distinctive momentum. Besides, we split the min-max optimization loops of adversarial training into two parallel processes to reduce the training cost. Experimental results on CIFAR-10 and ImageNet show that our method achieves better defense accuracy under UAP with less training cost than state-of-the-art baselines.

BibTeX
@inproceedings{icassp2022_defendingagainst,
  title = {Defending Against Universal Attack Via Curvature-Aware Category Adversarial Training},
  author = {Peilun Du and Xiaolong Zheng and Liang Liu and Huadong Ma},
  booktitle = {ICASSP 2022},
  year = {2022}
}
Defending Against Universal Attack Via Curvature-Aware Category Adversarial Training · ICASSP 2022