Abstract
Random defense represents a promising strategy to protect neural networks from adversarial attacks. Most of these methods enhance robustness by injecting randomness into the data, increasing uncertainty for attackers. However, this randomness could reduce the generalization capacity of defense, as defense performance could be sensitive to the hyperparameters of noise added to the data, making it difficult to generalize across different datasets. Additionally, the involvement of randomness always comes with a reduction of natural accuracy, which leads to a delicate trade-off between them, which is seldom studied in random defense. In this work, we propose incorporating randomness into the network structure instead of data input by designing stochastic deformable convolution, where a random mask replaces the convolutional offset. This process promotes data independence, enhancing generalization across datasets. To study the trade-off, we conduct a theoretical analysis of both robust and clean accuracy, from a perspective of gradient cosine similarity and natural inference. Based on the analysis, we reformulate the adversarial training in our random defense framework. Extensive experiments show that our method achieves SOTA adversarial robustness and clean accuracy compared with other random defense methods. Code is available at https://github.com/theSleepyPig/Deformable_Convolution_with_Stochasticity
© 2025 by the author(s).
© 2025 by the author(s).
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 42nd International Conference on Machine Learning (ICML 2025) |
| Publisher | ML Research Press |
| Pages | 41943-41958 |
| Publication status | Published - 13 Jul 2025 |
| Event | 42nd International Conference on Machine Learning (ICML 2025) - Vancouver Convention Center, Vancouver, Canada Duration: 13 Jul 2025 → 19 Jul 2025 https://icml.cc/Conferences/2025 |
Publication series
| Name | Proceedings of Machine Learning Research |
|---|---|
| Publisher | ML Research Press |
| Volume | 267 |
| ISSN (Electronic) | 2640-3498 |
Conference
| Conference | 42nd International Conference on Machine Learning (ICML 2025) |
|---|---|
| Abbreviated title | ICML 2025 |
| Place | Canada |
| City | Vancouver |
| Period | 13/07/25 → 19/07/25 |
| Internet address |
Funding
This work was supported in part by the Start-up Grant (No. 9610680) of the City University of Hong Kong, Young Scientist Fund (No. 62406265) of NSFC, and the Australian Research Council under Projects DP240101848 and FT230100549.
Fingerprint
Dive into the research topics of 'Adversarial Robustness via Deformable Convolution with Stochasticity'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver