Multi-view Defense with Adversarial Autoencoders.

Xuli Sun,Shiliang Sun
DOI: https://doi.org/10.1109/ijcnn52387.2021.9533337
2021-01-01
Abstract:In view of the vulnerability of multi-view deep models to adversarial perturbation, this paper designs two kinds of multi-view adversarial autoencoders (MAAEs). We first propose the MAAE1 defense, in which each view is used to train the corresponding single-view adversarial autoencoders separately, and then the reconstructed output is fed into the target model for classification. Based on the consistency and complementary principle, we further integrate the scheme of adjusting the weights of different views adaptively into the design of multi-view defense, referred to it as MAAE2. Experimental results verify that the proposed multi-view adversarial defense effectively enhances the adversarial robustness of the deep multi-view model without negatively affecting the classification accuracy in the original examples. Besides, MAAEs show superior adversarial robustness to unseen perturbations.
What problem does this paper attempt to address?