We introduce a novel approach to counter adversarial attacks, namely, image resampling. Image resampling transforms a discrete image into a new one, simulating the process of scene recapturing or rerendering as specified by a geometrical transformation. The underlying rationale behind our idea is that image resampling can alleviate the influence of adversarial perturbations while preserving essential semantic information, thereby conferring an inherent advantage in defending against adversarial attacks. To validate this concept, we present a comprehensive study on leveraging image resampling to defend against adversarial attacks. We have developed basic resampling methods that employ interpolation strategies and coordinate shifting magnitudes. Our analysis reveals that these basic methods can partially mitigate adversarial attacks. However, they come with apparent limitations: the accuracy of clean images noticeably decreases, while the improvement in accuracy on adversarial examples is not substantial. We propose implicit representation-driven image resampling (IRAD) to overcome these limitations. First, we construct an implicit continuous representation that enables us to represent any input image within a continuous coordinate space. Second, we introduce SampleNet, which automatically generates pixel-wise shifts for resampling in response to different inputs. Furthermore, we can extend our approach to the state-of-the-art diffusion-based method, accelerating it with fewer time steps while preserving its defense capability. Extensive experiments demonstrate that our method significantly enhances the adversarial robustness of diverse deep models against various attacks while maintaining high accuracy on clean images.
翻译:我们提出了一种应对对抗攻击的新方法——图像重采样。图像重采样将离散图像通过几何变换模拟场景重捕获或重渲染过程,转换为新图像。其核心思想在于:图像重采样能在保留关键语义信息的同时削弱对抗扰动的影响,从而天然具有防御对抗攻击的优势。为验证该概念,我们开展了利用图像重采样防御对抗攻击的全面研究。我们开发了采用插值策略与坐标偏移幅度的基础重采样方法。分析表明,这些基础方法可部分缓解对抗攻击,但存在明显局限:干净图像精度显著下降,而对抗样本精度提升有限。为此,我们提出隐式表示驱动的图像重采样(IRAD):首先构建隐式连续表示,实现任意输入图像在连续坐标空间中的表征;其次引入SampleNet,根据不同输入自动生成重采样所需的逐像素偏移。此外,本方法可扩展至前沿的扩散模型,在保持防御能力的同时以更少时间步加速运算。大量实验证明,本方法在维持干净图像高精度的前提下,能显著增强多种深度模型对各种攻击的对抗鲁棒性。