Skip to main navigation Skip to search Skip to main content

Adversarial Robustness via Deformable Convolution with Stochasticity

  • Yanxiang Ma (Co-first Author)
  • , Zixuan Huang (Co-first Author)
  • , Minjing Dong
  • , Shan You
  • , Chang Xu*
  • *Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Random defense represents a promising strategy to protect neural networks from adversarial attacks. Most of these methods enhance robustness by injecting randomness into the data, increasing uncertainty for attackers. However, this randomness could reduce the generalization capacity of defense, as defense performance could be sensitive to the hyperparameters of noise added to the data, making it difficult to generalize across different datasets. Additionally, the involvement of randomness always comes with a reduction of natural accuracy, which leads to a delicate trade-off between them, which is seldom studied in random defense. In this work, we propose incorporating randomness into the network structure instead of data input by designing stochastic deformable convolution, where a random mask replaces the convolutional offset. This process promotes data independence, enhancing generalization across datasets. To study the trade-off, we conduct a theoretical analysis of both robust and clean accuracy, from a perspective of gradient cosine similarity and natural inference. Based on the analysis, we reformulate the adversarial training in our random defense framework. Extensive experiments show that our method achieves SOTA adversarial robustness and clean accuracy compared with other random defense methods. Code is available at https://github.com/theSleepyPig/Deformable_Convolution_with_Stochasticity
© 2025 by the author(s).
Original languageEnglish
Title of host publicationProceedings of the 42nd International Conference on Machine Learning (ICML 2025)
PublisherML Research Press
Pages41943-41958
Publication statusPublished - 13 Jul 2025
Event42nd International Conference on Machine Learning (ICML 2025) - Vancouver Convention Center, Vancouver, Canada
Duration: 13 Jul 202519 Jul 2025
https://icml.cc/Conferences/2025

Publication series

NameProceedings of Machine Learning Research
PublisherML Research Press
Volume267
ISSN (Electronic)2640-3498

Conference

Conference42nd International Conference on Machine Learning (ICML 2025)
Abbreviated titleICML 2025
PlaceCanada
CityVancouver
Period13/07/2519/07/25
Internet address

Funding

This work was supported in part by the Start-up Grant (No. 9610680) of the City University of Hong Kong, Young Scientist Fund (No. 62406265) of NSFC, and the Australian Research Council under Projects DP240101848 and FT230100549.

Fingerprint

Dive into the research topics of 'Adversarial Robustness via Deformable Convolution with Stochasticity'. Together they form a unique fingerprint.

Cite this