AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Regular Paper

Combining Innovative CVTNet and Regularization Loss for Robust Adversarial Defense

Laboratory of Public Big Data, School of Computer Science and Technology, Guizhou University, Guiyang 550025, China
Show Author Information

Abstract

Deep neural networks (DNNs) are vulnerable to elaborately crafted and imperceptible adversarial perturbations. With the continuous development of adversarial attack methods, existing defense algorithms can no longer defend against them proficiently. Meanwhile, numerous studies have shown that vision transformer (ViT) has stronger robustness and generalization performance than the convolutional neural network (CNN) in various domains. Moreover, because the standard denoiser is subject to the error amplification effect, the prediction network cannot correctly classify all reconstruction examples. Firstly, this paper proposes a defense network (CVTNet) that combines CNNs and ViTs that is appended in front of the prediction network. CVTNet can effectively eliminate adversarial perturbations and maintain high robustness. Furthermore, this paper proposes a regularization loss ( LCPL), which optimizes the CVTNet by computing different losses for the correct prediction set (CPS) and the wrong prediction set (WPS) of the reconstruction examples, respectively. The evaluation results on several standard benchmark datasets show that CVTNet performs better robustness than other advanced methods. Compared with state-of-the-art algorithms, the proposed CVTNet defense improves the average accuracy of pixel-constrained attack examples generated on the CIFAR-10 dataset by 24.25% and spatially-constrained attack examples by 14.06%. Moreover, CVTNet shows excellent generalizability in cross-model protection.

Electronic Supplementary Material

Download File(s)
JCST-2306-13515-Highlights.pdf (618.1 KB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 1078-1093

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Wang W-D, Li Z, Zhang L. Combining Innovative CVTNet and Regularization Loss for Robust Adversarial Defense. Journal of Computer Science and Technology, 2024, 39(5): 1078-1093. https://doi.org/10.1007/s11390-024-3515-8

604

Views

1

Crossref

0

Web of Science

1

Scopus

0

CSCD

Received: 16 June 2023
Accepted: 10 April 2024
Published: 05 December 2024
© Institute of Computing Technology, Chinese Academy of Sciences 2024