Feature Extractor Distance Bounds for Adversarial Robustness
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing adversarial training methods for content-based image retrieval are limited as they rely on known attack methods and do not effectively address unknown attack methods, making it difficult to assess the impact of adversarial examples on search results.
Innovation Solution
A learning device and method that learns a feature extractor to minimize the upper and lower bounds of the distance between images in a feature space, allowing for robustness verification against unknown adversarial attacks by ensuring that the distance between images remains consistent even with noise perturbations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If adversarial training is performed using known attack methods, then the model becomes more robust against those specific attacks, but it remains vulnerable to unknown attack methods and cannot verify the degree of impact on search results
Solution Approach 1:
The patent uses adversarial examples (harmful inputs designed to attack the model) as training data to improve the model's robustness. By intentionally training with these malicious inputs, the model learns to resist both known and unknown attack methods, converting the harmful adversarial examples into beneficial training material that enhances overall security and verification capabilities.
2Adaptability or versatility
If the distance between images in feature space is allowed to vary widely, then the feature extractor can capture more diverse characteristics, but the system becomes vulnerable to adversarial perturbations that can manipulate search results
Solution Approach 1:
The patent modifies the distance metric parameters in the feature space by introducing upper and lower bound constraints. This parameter change ensures that the distance between images remains within a controlled range, preventing adversarial perturbations from arbitrarily manipulating search results while preserving the feature extractor's ability to capture diverse characteristics through proper feature learning.
Data Source
AI summary
A learning device causes a feature amount extractor to be trained such that the upper limit and the lower limit of a distance, obtained in a case where the feature amount extractor is used, in a feature space between images become close to the distance.


