Skip to main navigation Skip to search Skip to main content

Why does batch normalization induce the model vulnerability on adversarial images?

  • Fei Kong
  • , Fangqi Liu
  • , Kaidi Xu
  • , Xiaoshuang Shi*
  • *Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

Abstract

Batch normalization is one of the most widely used components in deep neural networks. It can accelerate training, and boost model performance on normal samples. However, batch normalization induces vulnerability to models on adversarial examples, especially in medical images, and the reason is still not clear. In this paper, we aim to explain the vulnerability aroused by batch normalization under adversarial images. Specifically, we first discover that both natural and medical images contain a large number of trivial features, whose weights will be enlarged under adversarial attacks, and batch normalization can further enlarge their weights. Additionally, we find that batch normalization will reduce the inter-class margin of high-level features, leading to less tolerance to adversarial perturbations, thereby decreasing the model robustness. Moreover, we hypothesize that the smaller inter-class margin, the more difficult to attain the optimal classification space, which means batch normalization will restrict the performance of adversarial training. This further verifies that a narrower inter-class margin induced by batch normalization reduces the model robustness. Experiments on four benchmark datasets demonstrate our discovery, interpretation and hypothesis. © 2022, The Author(s), under exclusive licence to Springer Science+Business Media, LLC, part of Springer Nature.
Original languageEnglish
Pages (from-to)1073-1091
Number of pages19
JournalWorld Wide Web
Volume26
Issue number3
Online published4 Jul 2022
DOIs
Publication statusPublished - May 2023
Externally publishedYes

Funding

This work is partially supported by the National Natural Science Foundation of China (Grant No: 61876046) and the Guangxi “Bagui” Teams for Innovation and Research.

Research Keywords

  • Adversarial examples
  • Batch normalization
  • Interpretation
  • Model robustness

Fingerprint

Dive into the research topics of 'Why does batch normalization induce the model vulnerability on adversarial images?'. Together they form a unique fingerprint.

Cite this