Dynamic Divide-and-Conquer Adversarial Training for Robust Semantic Segmentation

Xiaogang Xu,Hengshuang Zhao,Jiaya Jia
DOI: https://doi.org/10.1109/iccv48922.2021.00739
2021-01-01
Abstract:Adversarial training is promising for improving robustness of deep neuralnetworks towards adversarial perturbations, especially on the classificationtask. The effect of this type of training on semantic segmentation, contrarily,just commences. We make the initial attempt to explore the defense strategy onsemantic segmentation by formulating a general adversarial training procedurethat can perform decently on both adversarial and clean samples. We propose adynamic divide-and-conquer adversarial training (DDC-AT) strategy to enhancethe defense effect, by setting additional branches in the target model duringtraining, and dealing with pixels with diverse properties towards adversarialperturbation. Our dynamical division mechanism divides pixels into multiplebranches automatically. Note all these additional branches can be abandonedduring inference and thus leave no extra parameter and computation cost.Extensive experiments with various segmentation models are conducted on PASCALVOC 2012 and Cityscapes datasets, in which DDC-AT yields satisfying performanceunder both white- and black-box attack.
What problem does this paper attempt to address?