Abstract
Though being remarkably efficient in computation and storage, recent research demonstrates deep hashing based image retrieval models are also vulnerable to adversarial attacks. A substantial amount of defence techniques against adversarial attacks have been developed recently, the overwhelming majority focus on adversarial training. However, adversarial defence focusing on the data side, i.e., cluster-contrasting, still remains a paucity. Albeit a pioneer work makes attempt to maximise the average distances of image clusters by anchoring predefined hash centers, it is still insufficient for a robust defence due to no optimal guarantee and over-sticking to the global average distance. Further, the laser-focus of either adversarial training or cluster contrasting of existing methods hinder them from further robustness boosting by judiciously incorporating them together. In this paper, we propose a novel distance maximization algorithm for defence on deep hashing based image retrieval systems. The model finds the optimal maximum average distance between cluster centers, and then uses a heuristic method to increase the minimum distance in the worst-case by solving a maximum Boolean satisfiability (max-SAT) problem. Our proposed distance maximization algorithm is a boosting algorithm that can be incorporated into adversarial training to enhance or boost the robustness of retrieval systems. Experiments conducted on two datasets demonstrate that our algorithm can generate clusters with a maximised average distance, while the minimum distance is also increased by up to 33% over the state-of-the-art method, and robustness is improved by up to 23 %.
Original language | English |
---|---|
Title of host publication | Proceedings of the IEEE International Conference on Knowledge Graph (ICKG), 1-2 December 2023, Shanghai, China |
Editors | Victor S. Sheng, Chindo Hicks, Charles Ling, Vijay Raghavan, Xindong Wu |
Place of Publication | U.S. |
Publisher | IEEE |
Pages | 176-183 |
Number of pages | 8 |
ISBN (Electronic) | 9798350307092 |
DOIs | |
Publication status | Published - 2023 |
Externally published | Yes |
Event | IEEE International Conference on Knowledge Graph - Shanghai World Trade Mall, Shanghai, China Duration: 1 Dec 2023 → 2 Dec 2023 Conference number: 14th |
Conference
Conference | IEEE International Conference on Knowledge Graph |
---|---|
Abbreviated title | ICKG |
Country/Territory | China |
City | Shanghai |
Period | 1/12/23 → 2/12/23 |
Keywords
- Training
- Machine learning algorithms
- Image retrieval
- Clustering algorithms
- Knowledge graphs
- Boosting
- Robustness
- Adversarial Machine Learning
- Adversarial Defence
- Deep Hashing
- Image Retrieval