Projects per year
Abstract
The escalating threat of adversarial attacks on deep learning models, particularly in security-critical fields, has highlighted the need for robust deep learning systems. Conventional evaluation methods of their robustness rely on adversarial accuracy, which measures the model performance under a specific perturbation intensity. However, this singular metric does not fully encapsulate the overall resilience of a model against varying degrees of perturbation. To address this issue, we propose a new metric termed as the adversarial hypervolume for assessing the robustness of deep learning models comprehensively over a range of perturbation intensities from a multi-objective optimization standpoint. This metric allows for an in-depth comparison of defense mechanisms and recognizes the trivial improvements in robustness brought by less potent defensive strategies. We adopt a novel training algorithm to enhance adversarial robustness uniformly across various perturbation intensities, instead of only optimizing adversarial accuracy. Our experiments validate the effectiveness of the adversarial hypervolume metric in robustness evaluation, demonstrating its ability to reveal subtle differences in robustness that adversarial accuracy overlooks. © 2025 IEEE
| Original language | English |
|---|---|
| Pages (from-to) | 1367 - 1378 |
| Journal | IEEE Transactions on Emerging Topics in Computational Intelligence |
| Volume | 9 |
| Issue number | 2 |
| Online published | 13 Jan 2025 |
| DOIs | |
| Publication status | Published - Apr 2025 |
Funding
This work was supported by the Research Grants Council of the Hong Kong Special Administrative Region under Grant CityU11215622 and Grant CityU11215723.
Research Keywords
- Adversarial attacks
- multiobjective optimization
- hypervolume
RGC Funding Information
- RGC-funded
Fingerprint
Dive into the research topics of 'Exploring the Adversarial Frontier: Quantifying Robustness via Adversarial Hypervolume'. Together they form a unique fingerprint.Projects
- 2 Active
-
GRF: Exactness and Component Sharing in Expensive Evolutionary Multiobjective Optimization
ZHANG, Q. (Principal Investigator / Project Coordinator)
1/01/24 → …
Project: Research
-
GRF: Few for Many: A Non-Pareto Approach for Many Objective Optimization
ZHANG, Q. (Principal Investigator / Project Coordinator)
1/01/23 → …
Project: Research
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver