HF-Defend: Defending Against Adversarial Examples Based on Halftoning

Gaozhi Liu,Sheng Li,Zhenxing Qian,Xinpeng Zhang
DOI: https://doi.org/10.1109/mmsp55362.2022.9948798
2022-01-01
Abstract:How to deal with the adversarial examples attracts a lot of interest recently. In this paper, we propose HF-Defend: a novel method to defend against the adversarial examples based on halftoning. Unlike the existing schemes, HF-Defend thoroughly removes the adversarial perturbations by transforming a 8-bit grayscale image (or one of the RGB channels in a color image) into a 1-bit halftoned image. To maintain the image quality and content, we propose a reconstruction module for the recovery of both the main contents and fine details of the image. In particular, we newly design a non-linear low-pass filter to extract the main contents, and a FilterNet to establish a high-pass filter for the reconstruction of fine details. Experimental results demonstrate the advantage of our HF-Defend over the existing schemes.
What problem does this paper attempt to address?