Skip to main navigation Skip to search Skip to main content

F2AT: Feature-Focusing Adversarial Training via Disentanglement of Natural and Perturbed Patterns

  • Yaguan Qian
  • , Chenyu Zhao
  • , Zhaoquan Gu*
  • , Bin Wang*
  • , Shouling Ji
  • , Wei Wang
  • , Yanchun Zhang
  • *Corresponding author for this work
  • Zhejiang University of Science and Technology
  • Harbin Institute of Technology
  • Zhejiang Key Laboratory of Multidimensional Perception Technology
  • Zhejiang University
  • Xi'an Jiaotong University
  • Victoria University
  • Zhejiang Normal University

Research output: Contribution to journalArticlepeer-review

Abstract

Deep neural networks (DNNs) are vulnerable to adversarial examples crafted by well-designed perturbations. This could lead to disastrous results on critical applications such as self-driving cars, surveillance security, and medical diagnosis. At present, adversarial training is one of the most effective defenses against adversarial examples. However, in traditional adversarial training, it is still difficult to achieve a good trade-off between clean accuracy and robustness since DNNs still learn spurious features. The intrinsic reason is that traditional adversarial training makes it difficult to fully learn core features from adversarial examples when noise and examples cannot be disentangled. In this paper, we disentangle the adversarial examples into natural and perturbed patterns by bit-plane slicing. We assume the higher bit-planes represent natural patterns and the lower bit-planes represent perturbed patterns, respectively. We propose Feature-Focusing Adversarial Training (F2AT), which differs from previous work in that it enforces the model to focus on the core features from natural patterns and reduce the impact of spurious features from perturbed patterns. The experimental results demonstrated that the clean accuracy and adversarial robustness with our F2AT can be significantly improved.

Original languageEnglish
Pages (from-to)5201-5213
Number of pages13
JournalIEEE Transactions on Knowledge and Data Engineering
Volume37
Issue number9
DOIs
StatePublished - 2025
Externally publishedYes

Keywords

  • Adversarial example
  • adversarial training
  • robustness
  • trade-off

Fingerprint

Dive into the research topics of 'F2AT: Feature-Focusing Adversarial Training via Disentanglement of Natural and Perturbed Patterns'. Together they form a unique fingerprint.

Cite this