상세 보기
Robustness-Aware Filter Pruning for Robust Neural Networks Against Adversarial Attacks
- Lim, Hyuntak;
- Roh, Si-Dong;
- Park, Sangki;
- Chung, Ki-Seok
WEB OF SCIENCE
3SCOPUS
4초록
Today, neural networks show remarkable performance in various computer vision tasks, but they are vulnerable to adversarial attacks. By adversarial training, neural networks may improve robustness against adversarial attacks. However, it is a time-consuming and resource-intensive task. An earlier study analyzed adversarial attacks on the image features and proposed a robust dataset that would contain only features robust to the adversarial attack. By training with the robust dataset, neural networks can achieve a decent accuracy under adversarial attacks without carrying out time-consuming adversarial perturbation tasks. However, even if a network is trained with the robust dataset, it may still be vulnerable to adversarial attacks. In this paper, to overcome this limitation, we propose a new method called Robustness-Aware Filter Pruning (RFP). To the best of our knowledge, it is the first attempt to utilize a filter pruning method to enhance the robustness against the adversarial attack. In the proposed method, the filters that are involved with non-robust features are pruned. With the proposed method, 52.1 % accuracy against one of the most powerful adversarial attacks is achieved, which is 3.8% better than the previous robust dataset training while maintaining clean image test accuracy. Also, our method achieves the best performance when compared with the other filter pruning methods on robust dataset.
키워드
- 제목
- Robustness-Aware Filter Pruning for Robust Neural Networks Against Adversarial Attacks
- 저자
- Lim, Hyuntak; Roh, Si-Dong; Park, Sangki; Chung, Ki-Seok
- 발행일
- 2021-11
- 유형
- Proceedings Paper
- 저널명
- 2021 IEEE 31ST INTERNATIONAL WORKSHOP ON MACHINE LEARNING FOR SIGNAL PROCESSING (MLSP)
- 권
- 2021
- 호
- October
- 페이지
- 1 ~ 6