Skip to main navigation Skip to search Skip to main content

Supervised Mixup: Protecting the Likely Classes for Adversarial Robustness

  • Indian Institute of Science Education and Research Bhopal
  • Indian Institute of Technology Jodhpur

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Deep neural networks have demonstrated remarkable effectiveness across various applications. However, their vulnerability to intelligently crafted adversarial attacks is well-documented. The literature shows that deep networks often rely on common low-level features, such as edges and textures, which are present across different object classes. For instance, classes such as cars, trucks, and ships, which belong to the broader category of automobiles, share similar characteristics. We hypothesize that these similarities make it easier for subtle adversarial noise to misclassify images into closely related classes within the feature space. Building on these insights, this research aims to enhance the robustness of deep learning algorithms by protecting classes that are likely to be misclassified. We introduce a novel data augmentation technique called Supervised Mixup, designed to retrain networks to better distinguish between closely related classes and resist various forms of subtle adversarial noise. This augmentation-based defense is attack-agnostic, making it applicable across various attacks and vulnerable pre-trained networks. Extensive experiments conducted on multiple datasets, under challenging scenarios including gray-box and white-box attacks, demonstrate the superiority of the proposed algorithm compared to recent state-of-the-art defense and data augmentation methods.

Original languageEnglish
Title of host publicationPattern Recognition - 27th International Conference, ICPR 2024, Proceedings
EditorsApostolos Antonacopoulos, Subhasis Chaudhuri, Rama Chellappa, Cheng-Lin Liu, Saumik Bhattacharya, Umapada Pal
PublisherSpringer Science and Business Media Deutschland GmbH
Pages30-45
Number of pages16
ISBN (Print)9783031781681
DOIs
StatePublished - 2025
Event27th International Conference on Pattern Recognition, ICPR 2024 - Kolkata, India
Duration: Dec 1 2024Dec 5 2024

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume15305 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference27th International Conference on Pattern Recognition, ICPR 2024
Country/TerritoryIndia
CityKolkata
Period12/1/2412/5/24

Keywords

  • Adversarial Defense
  • Adversarial attacks
  • Classwise security
  • Data augmentation
  • Deep neural networks
  • Vulnerability

Fingerprint

Dive into the research topics of 'Supervised Mixup: Protecting the Likely Classes for Adversarial Robustness'. Together they form a unique fingerprint.

Cite this