Denoised Internal Models: A Brain-inspired Autoencoder Against Adversarial Attacks

Denoised Internal Models: A Brain-inspired Autoencoder Against Adversarial Attacks
复制标题

DOI:
10.1007/s11633-022-1375-7
复制
发表时间:
2021-11
期刊:
Machine Intelligence Research
影响因子:
--
通讯作者:
Kaiyuan Liu;Xingyu Li;Yu-Rui Lai;Hang Su;Jiacheng Wang;Chunxu Guo;Hong Xie;J. Guan;
Kaiyuan Liu;Xingyu Li;Yu-Rui Lai;Hang Su;Jiacheng Wang;Chunxu Guo;Hong Xie;J. Guan;
中科院分区:
其他
文献类型:
--
作者:
Kaiyuan Liu;Xingyu Li;Yu-Rui Lai;Hang Su;Jiacheng Wang;Chunxu Guo;Hong Xie;J. Guan;

文献摘要

相似文献

尽管取得了巨大的成功,但深度学习严重缺乏鲁棒性;即,深度神经网络非常容易受到对抗性攻击,即使是最简单的攻击。受脑科学最新进展的启发,我们提出了去噪内部模型(DIM),这是一种新的基于生成自动编码器的模型来应对这一挑战。DIM模拟人脑中用于视觉信号处理的管道,采用两阶段方法。在第一阶段,DIM使用去噪器来降低噪声和输入的维数,反映了丘脑的信息预处理。受初级视觉皮层中与记忆相关的痕迹的稀疏编码的启发,第二阶段产生一组内部模型,每个类别一个。我们对DIM进行了42次对抗性攻击的评估,结果表明DIM有效地防御了所有攻击,并且在MNIST(修改后的国家标准与技术研究所)数据集上的整体鲁棒性方面优于SOTA。
Despite its great success, deep learning severely suffers from robustness; i.e., deep neural networks are very vulnerable to adversarial attacks, even the simplest ones. Inspired by recent advances in brain science, we propose the denoised internal models (DIM), a novel generative autoencoder-based model to tackle this challenge. Simulating the pipeline in the human brain for visual signal processing, DIM adopts a two-stage approach. In the first stage, DIM uses a denoiser to reduce the noise and the dimensions of inputs, reflecting the information pre-processing in the thalamus. Inspired by the sparse coding of memory-related traces in the primary visual cortex, the second stage produces a set of internal models, one for each category. We evaluate DIM over 42 adversarial attacks, showing that DIM effectively defenses against all the attacks and outperforms the SOTA on the overall robustness on the MNIST (Modified National Institute of Standards and Technology) dataset.