Non-informative Noise-Enhanced Stochastic Neural Networks for Improving Adversarial Robustness

Hao Yang,Min Wang,Qi Wang,Zhengfei Yu,Guangyin Jin,Chunlai Zhou,Yun Zhou
DOI: https://doi.org/10.1016/j.inffus.2024.102397
IF: 18.6
2024-01-01
Information Fusion
Abstract:Stochastic Neural Networks (SNNs) have emerged as a promising tool for improving model adversarial robustness by injecting uncertainty into model activations or weights. However, the current implementations are dominated by injecting fixed Gaussian noises. Despite its ease of use, Gaussian distribution also has several limitations, e.g., inaccurate uncertainty estimation due to its unimodality. In this paper, we propose a noninformative noise -enhanced Stochastic Neural Network (NINE-SNN), which relaxes the Gaussian distribution to a non -informative prior arbitrary distribution and encourages the model to learn an appropriate uncertainty. We provide theoretical insights showing that by adding increasing levels of stochastic noise to a DNN, the model naturally becomes more resistant to input perturbations. We evaluate the proposed method on various benchmarks of architectures and well-known white -box and black -box attacks. The results show that the proposed method achieves state-of-the-art performances without adversarial training, demonstrating the superiority and efficiency of NINE-SNN. Compared to adversarial training, NINE-SNN has saved about 7x computation time cost, and has nearly no accuracy loss for clean data accuracy. Moreover, it achieves SOTA results in SNNs network architectures and Non -stochastic network architectures in robust data accuracy.
What problem does this paper attempt to address?