AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (905.7 KB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Article | Open Access

An Effective Adversarial Defense Framework: From Robust Feature Perspective

Baolin Li1Tao Hu1,2,3( )Xinlei Liu1Jichao Xie1Peng Yi1,2,3
Information Engineering University, Zhengzhou, 450000, China
Key Laboratory of Cyberspace Security, Ministry of Education of China, Zhengzhou, 450000, China
National Key Laboratory of Advanced Communication Networks, Zhengzhou, 450000, China
Show Author Information

Abstract

Deep neural networks are known to be vulnerable to adversarial attacks. Unfortunately, the underlying mechanisms remain insufficiently understood, leading to empirical defenses that often fail against new attacks. In this paper, we explain adversarial attacks from the perspective of robust features, and propose a novel Generative Adversarial Network (GAN)-based Robust Feature Disentanglement framework (GRFD) for adversarial defense. The core of GRFD is an adversarial disentanglement structure comprising a generator and a discriminator. For the generator, we introduce a novel Latent Variable Constrained Variational Auto-Encoder (LVCVAE), which enhances the typical beta-VAE with a constrained rectification module to enforce explicit clustering of latent variables. To supervise the disentanglement of robust features, we design a Robust Supervisory Model (RSM) as the discriminator, sharing architectural alignment with the target model. The key innovation of RSM is our proposed Feature Robustness Metric (FRM), which serves as part of the training loss and synthesizes the classification ability of features as well as their resistance to perturbations. Extensive experiments on three benchmark datasets demonstrate the superiority of GRFD: it achieves 93.69% adversarial accuracy on MNIST, 77.21% on CIFAR10, and 58.91% on CIFAR100 with minimal degradation in clean accuracy. Codes are available at: https://github.com/brother2cat/GRFD (accessed on 23 July 2025).

References

【1】
【1】
 
 
Computers, Materials & Continua
Pages 2141-2155

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Li B, Hu T, Liu X, et al. An Effective Adversarial Defense Framework: From Robust Feature Perspective. Computers, Materials & Continua, 2025, 85(1): 2141-2155. https://doi.org/10.32604/cmc.2025.066370

300

Views

3

Downloads

2

Crossref

1

Web of Science

2

Scopus

Received: 07 April 2025
Accepted: 24 July 2025
Published: 29 August 2025
© The Author 2024.

This work is licensed under a Creative Commons Attribution 4.0 International License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.