Skip to main navigation Skip to search Skip to main content

Improve Adversarial Robustness of MNIST Classification via Topological Data Analysis

  • Yining Liu
  • , Xiao Li
  • , Sitian Qin*
  • , Xiaolin Hu*
  • *Corresponding author for this work
  • Harbin Institute of Technology Weihai
  • Tsinghua University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Current defense methods for machine learning classification tasks against adversarial samples mostly focus on the propagation process of networks rather than leveraging the shape characteristics of target objects, as humans perform object recognition. We propose a novel approach named Topological Random Forest (TPRF) that captures the position and shape information of digits using topological features extracted via Topological Data Analysis (TDA) and combines it with a neural network trained with CROWN-IBP to improve the adversarial robustness of the classification on the MNIST dataset. We illustrate the process of topological feature extraction and explain the classification principle, which is compatible with the human recognition process. Experimental results show that TPRF achieves comparable clean and robust accuracies to state-of-the-art (SOTA) CNNs. We also conduct an analysis of misclassification cases, which offers insights valuable for further exploration of object recognition models that rely on shape bias.

Original languageEnglish
Title of host publicationAdvances in Neural Networks – ISNN 2024 - 18th International Symposium on Neural Networks, 2024, Proceedings
EditorsXinyi Le, Zhijun Zhang
PublisherSpringer Science and Business Media Deutschland GmbH
Pages143-152
Number of pages10
ISBN (Print)9789819743988
DOIs
StatePublished - 2024
Externally publishedYes
Event18th International Symposium on Neural Networks, ISNN 2024 - Weihai, China
Duration: 11 Jul 202414 Jul 2024

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume14827 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference18th International Symposium on Neural Networks, ISNN 2024
Country/TerritoryChina
CityWeihai
Period11/07/2414/07/24

Keywords

  • Adversarial robustness
  • Persistent homology
  • Topolpgical data analysis

Fingerprint

Dive into the research topics of 'Improve Adversarial Robustness of MNIST Classification via Topological Data Analysis'. Together they form a unique fingerprint.

Cite this