Robustness of Rotation-Equivariant Networks to Adversarial Perturbations
arXiv:1802.06627
Abstract
Deep neural networks have been shown to be vulnerable to adversarial examples: very small perturbations of the input having a dramatic impact on the predictions. A wealth of adversarial attacks and distance metrics to quantify the similarity between natural and adversarial images have been proposed, recently enlarging the scope of adversarial examples with geometric transformations beyond pixel-wise attacks. In this context, we investigate the robustness to adversarial attacks of new Convolutional Neural Network architectures providing equivariance to rotations. We found that rotation-equivariant networks are significantly less vulnerable to geometric-based attacks than regular networks on the MNIST, CIFAR-10, and ImageNet datasets.
4 pages + references; public implementation of Spatially Transformed Adversarial Examples can be found at https://github.com/rakutentech/stAdv
References in corpus (6)
- On the Generalization of Equivariance and Convolution in Neural Networks to the Action of Compact Groups
- Spatially Transformed Adversarial Examples
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- Towards Imperceptible and Robust Adversarial Example Attacks against Neural Networks
- Learning Steerable Filters for Rotation Equivariant CNNs
- Geometric robustness of deep networks: analysis and improvement
Cited by in corpus (13)
- Motivating the Rules of the Game for Adversarial Example Research
- Adversarial Training against Location-Optimized Adversarial Patches
- Adversarial Examples - A Complete Characterisation of the Phenomenon
- Adversarial Examples on Object Recognition: A Comprehensive Survey
- Invariance-inducing regularization using worst-case transformations suffices to boost accuracy and spatial robustness
- Rotational 3D Texture Classification Using Group Equivariant CNNs
- Model-Based Robust Deep Learning: Generalizing to Natural, Out-of-Distribution Data
- Perturbations are not Enough: Generating Adversarial Examples with Spatial Distortions
- Recurrent Attention Model with Log-Polar Mapping is Robust against Adversarial Attacks
- Rotation Equivariant CNNs for Digital Pathology
- Convolutional Neural Networks with Transformed Input based on Robust Tensor Network Decomposition
- Self-Refining Deep Symmetry Enhanced Network for Rain Removal
- On Universalized Adversarial and Invariant Perturbations