Please use this identifier to cite or link to this item:
https://dspace.iiti.ac.in/handle/123456789/11111
Title: | Dynamic Hypersphere Embedding Scale Against Adversarial Attacks |
Authors: | Tanveer, M. |
Keywords: | Antennas;Behavioral research;Deep learning;Degradation;Gradient methods;Integrated circuits;Timing circuits;Adversarial attack;Adversarial defense;Behavioral science;Computational modelling;Deep learning;Embeddings;Integrated circuit modeling;Max-margin learning;Robustness;Embeddings |
Issue Date: | 2022 |
Publisher: | Institute of Electrical and Electronics Engineers Inc. |
Citation: | Hassanin, M., Moustafa, N., Razzak, I., Tanveer, M., Ormrod, D., & Slay, J. (2022). Dynamic hypersphere embedding scale against adversarial attacks. IEEE Transactions on Engineering Management, , 1-12. doi:10.1109/TEM.2022.3194487 |
Abstract: | Learning robust features against adversarial attacks is a challenging task that requires highly complex models, especially on aerial images, because they are subject to environmental and adversarial changes. Embedding hypersphere normalization, along with adversarial settings, causes performance degradation and enables the feature to overlap. To address this, in this article, we propose a dynamic hypersphere embedding scale (DHS) method that remaps the normalized features to a relative scale to learn robust features. The proposed method combines the benefits of hypersphere embedding without scarifying softmax advantages. The DHS aggregates the normalized features and the non-normalized ones. It uses a hypersphere embedding to enforce maximum-margin to the features that yield shorter magnitude and utilizes a dynamic scale to avoid features overlapping in the case of adversarial attacks. We validate the DHS' s effectiveness by embedding the adversarial training attacks such as Projected Gradient Descent (PGD), CW, and DeepFool. Empirical experiments revealed that the DHS improves the model performance by 12% when using the PGD attack, with less computation than legacy hypersphere models. Another set of experiments showed that the DHS does not obfuscate the gradient. IEEE |
URI: | https://doi.org/10.1109/TEM.2022.3194487 https://dspace.iiti.ac.in/handle/123456789/11111 |
ISSN: | 0018-9391 |
Type of Material: | Journal Article |
Appears in Collections: | Department of Mathematics |
Files in This Item:
There are no files associated with this item.
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.
Altmetric Badge: