Skip to main navigation Skip to search Skip to main content

Adversarial Attacks and Batch Normalization: A Batch Statistics Perspective

Research output: Contribution to journalArticlepeer-review

11 Citations (Scopus)

Abstract

Batch Normalization (BatchNorm) is an effective architectural component in deep learning models that helps to improve model performance and speed up training. However, it has also been found to increase the vulnerability of models to adversarial attacks. In this study, we investigate the mechanism behind this vulnerability and took first steps towards a solution called RobustNorm. We observed that adversarial inputs tend to shift the distributions of the output of the BatchNorm layer, leading to inaccurate train-time statistics and increased vulnerability. Through a series of experiments on various architectures and datasets, we confirm our hypothesis. We also demonstrate the effectiveness of RobustNorm in improving the robustness of models under adversarial perturbation while maintaining the benefits of BatchNorm.

Original languageEnglish
Pages (from-to)96449-96459
Number of pages11
JournalIEEE Access
Volume11
DOIs
Publication statusPublished - 2023

Bibliographical note

Publisher Copyright:
© 2013 IEEE.

Keywords

  • Batch normalization
  • adversarial robustness
  • transfer learning

Fingerprint

Dive into the research topics of 'Adversarial Attacks and Batch Normalization: A Batch Statistics Perspective'. Together they form a unique fingerprint.

Cite this