In recent years, there has been growing concern over the vulnerability of convolutional neural networks (CNNs) to image perturbations. However, achieving general robustness against different types of perturbations remains challenging, in which enhancing robustness to some perturbations (e.g., adversarial perturbations) may degrade others (e.g., common corruptions). In this paper, we demonstrate that adversarial training with an emphasis on phase components significantly improves model performance on clean, adversarial, and common corruption accuracies. We propose a frequency-based data augmentation method, Adversarial Amplitude Swap, that swaps the amplitude spectrum between clean and adversarial images to generate two novel training images: adversarial amplitude and adversarial phase images. These images act as substitutes for adversarial images and can be implemented in various adversarial training setups. Through extensive experiments, we demonstrate that our method enables the CNNs to gain general robustness against different types of perturbations and results in a uniform performance against all types of common corruptions.
翻译:近年来,卷积神经网络(CNN)对图像扰动的脆弱性引发了广泛关注。然而,实现针对不同类型扰动的通用鲁棒性仍具挑战性,其中增强对某些扰动(如对抗扰动)的鲁棒性可能会降低对其他扰动(如常见损坏)的鲁棒性。本文证明,重点强调相位分量的对抗训练能显著提升模型在干净图像、对抗扰动和常见损坏上的准确性。我们提出一种基于频率的数据增强方法——对抗幅度交换(Adversarial Amplitude Swap),该方法通过交换干净图像与对抗图像的幅度谱,生成两种新型训练图像:对抗幅度图像与对抗相位图像。这些图像可作为对抗图像的替代品,并能在不同对抗训练设置中实现。通过大量实验,我们证明该方法使CNN获得针对不同类型扰动的通用鲁棒性,并对所有类型常见损坏实现一致的性能表现。