CVFeb 26, 2024

Edge Detectors Can Make Deep Convolutional Neural Networks More Robust

arXiv:2402.16479v23 citationsh-index: 7
Originality Incremental advance
AI Analysis

This work addresses robustness in safety-critical applications like autonomous driving, but it is incremental as it builds on existing methods by adding edge features.

The paper tackles the vulnerability of deep convolutional neural networks to adversarial perturbations by introducing a binary edge feature branch (BEFB) that integrates edge detectors into backbones like VGG16 and ResNet34. Experimental results show that BEFB-integrated models achieve better accuracy than original models under FGSM, PGD, and C&W attacks on multiple datasets.

Deep convolutional neural networks (DCNN for short) are vulnerable to examples with small perturbations. Improving DCNN's robustness is of great significance to the safety-critical applications, such as autonomous driving and industry automation. Inspired by the principal way that human eyes recognize objects, i.e., largely relying on the shape features, this paper first employs the edge detectors as layer kernels and designs a binary edge feature branch (BEFB for short) to learn the binary edge features, which can be easily integrated into any popular backbone. The four edge detectors can learn the horizontal, vertical, positive diagonal, and negative diagonal edge features, respectively, and the branch is stacked by multiple Sobel layers (using edge detectors as kernels) and one threshold layer. The binary edge features learned by the branch, concatenated with the texture features learned by the backbone, are fed into the fully connected layers for classification. We integrate the proposed branch into VGG16 and ResNet34, respectively, and conduct experiments on multiple datasets. Experimental results demonstrate the BEFB is lightweight and has no side effects on training. And the accuracy of the BEFB integrated models is better than the original ones on all datasets when facing FGSM, PGD, and C\&W attacks. Besides, BEFB integrated models equipped with the robustness enhancing techniques can achieve better classification accuracy compared to the original models. The work in this paper for the first time shows it is feasible to enhance the robustness of DCNNs through combining both shape-like features and texture features.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes