Pith. sign in

REVIEW 1 cited by

Enhancing the "Immunity" of Mixture-of-Experts Networks for Adversarial Defense

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2402.18787 v1 pith:Y5OUGDBM submitted 2024-02-29 cs.LG cs.CR

classification cs.LGcs.CR
keywords adversarialnetworksdefensednnsevaluationimmunityinformationinnovative
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Recent studies have revealed the vulnerability of Deep Neural Networks (DNNs) to adversarial examples, which can easily fool DNNs into making incorrect predictions. To mitigate this deficiency, we propose a novel adversarial defense method called "Immunity" (Innovative MoE with MUtual information \& positioN stabilITY) based on a modified Mixture-of-Experts (MoE) architecture in this work. The key enhancements to the standard MoE are two-fold: 1) integrating of Random Switch Gates (RSGs) to obtain diverse network structures via random permutation of RSG parameters at evaluation time, despite of RSGs being determined after one-time training; 2) devising innovative Mutual Information (MI)-based and Position Stability-based loss functions by capitalizing on Grad-CAM's explanatory power to increase the diversity and the causality of expert networks. Notably, our MI-based loss operates directly on the heatmaps, thereby inducing subtler negative impacts on the classification performance when compared to other losses of the same type, theoretically. Extensive evaluation validates the efficacy of the proposed approach in improving adversarial robustness against a wide range of attacks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Towards Adversarial Robustness of Model-Level Mixture-of-Experts Architectures for Semantic Segmentation

    cs.CV 2024-12 conditional novelty 5.0 of 10

    Model-level mixtures of experts for semantic segmentation are, in most tested settings, more robust to white-box adversarial attacks than fixed ensembles, but the advantage disappears under universal attacks.

Pith tools