TY - GEN
T1 - Supervised Mixup
T2 - 27th International Conference on Pattern Recognition, ICPR 2024
AU - Agarwal, Akshay
AU - Vatsa, Mayank
AU - Singh, Richa
AU - Ratha, Nalini
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.
PY - 2025
Y1 - 2025
N2 - Deep neural networks have demonstrated remarkable effectiveness across various applications. However, their vulnerability to intelligently crafted adversarial attacks is well-documented. The literature shows that deep networks often rely on common low-level features, such as edges and textures, which are present across different object classes. For instance, classes such as cars, trucks, and ships, which belong to the broader category of automobiles, share similar characteristics. We hypothesize that these similarities make it easier for subtle adversarial noise to misclassify images into closely related classes within the feature space. Building on these insights, this research aims to enhance the robustness of deep learning algorithms by protecting classes that are likely to be misclassified. We introduce a novel data augmentation technique called Supervised Mixup, designed to retrain networks to better distinguish between closely related classes and resist various forms of subtle adversarial noise. This augmentation-based defense is attack-agnostic, making it applicable across various attacks and vulnerable pre-trained networks. Extensive experiments conducted on multiple datasets, under challenging scenarios including gray-box and white-box attacks, demonstrate the superiority of the proposed algorithm compared to recent state-of-the-art defense and data augmentation methods.
AB - Deep neural networks have demonstrated remarkable effectiveness across various applications. However, their vulnerability to intelligently crafted adversarial attacks is well-documented. The literature shows that deep networks often rely on common low-level features, such as edges and textures, which are present across different object classes. For instance, classes such as cars, trucks, and ships, which belong to the broader category of automobiles, share similar characteristics. We hypothesize that these similarities make it easier for subtle adversarial noise to misclassify images into closely related classes within the feature space. Building on these insights, this research aims to enhance the robustness of deep learning algorithms by protecting classes that are likely to be misclassified. We introduce a novel data augmentation technique called Supervised Mixup, designed to retrain networks to better distinguish between closely related classes and resist various forms of subtle adversarial noise. This augmentation-based defense is attack-agnostic, making it applicable across various attacks and vulnerable pre-trained networks. Extensive experiments conducted on multiple datasets, under challenging scenarios including gray-box and white-box attacks, demonstrate the superiority of the proposed algorithm compared to recent state-of-the-art defense and data augmentation methods.
KW - Adversarial Defense
KW - Adversarial attacks
KW - Classwise security
KW - Data augmentation
KW - Deep neural networks
KW - Vulnerability
UR - https://www.scopus.com/pages/publications/85211370437
U2 - 10.1007/978-3-031-78169-8_3
DO - 10.1007/978-3-031-78169-8_3
M3 - Conference contribution
AN - SCOPUS:85211370437
SN - 9783031781681
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 30
EP - 45
BT - Pattern Recognition - 27th International Conference, ICPR 2024, Proceedings
A2 - Antonacopoulos, Apostolos
A2 - Chaudhuri, Subhasis
A2 - Chellappa, Rama
A2 - Liu, Cheng-Lin
A2 - Bhattacharya, Saumik
A2 - Pal, Umapada
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 1 December 2024 through 5 December 2024
ER -