Related Experiment Videos
FAFA: A frequency-aware adversarial robust fairness algorithm
Jiachun Li1, Cheng Yan1, Suixin Zheng1
1School of Computer Science and Engineering, South China University of Technology, Guangzhou, 510006, Guangdong, China.
None:
With the wide application of deep neural networks, the research on adversarial robustness has become one of hotspots, especially the issue of fairness in adversarial robustness has garnered the wide attention. Significant disparities in adversarial robustness across different classes could degrade the overall performance, because the effectiveness of the defense mechanism is constrained by the class with the lowest robustness called the worst class, that is the phenomenon known as the "wooden barrel effect". Most of the existing robust fairness algorithms were designed based on specific experimental metrics, neglecting analyzing the intrinsic causes of the robust fairness. And the trade-off of robust contribution between easy and hard classes was not considered. In addition, the robust balance between hard classes and their similar classes was ignored too. The above issues actually limited the further improvement of robust fairness. Therefore, A Frequency-Aware Adversarial Robust Fairness Algorithm (FAFA for short), which explores the inherent causes of fairness issues from frequency perspective, is proposed in the paper. And a Frequency-Aware Fair Adversarial Training method called FAAT based on the contribution of frequency components is introduced, and different loss weights and perturbation constraints are assigned to various classes to enhance the robustness of hard classes. Additionally, a Frequency-Aware Fair Fine-tuning Algorithm (FAFT) which redistributes features between hard classes and their similar classes is implemented, achieving a more balanced robustness distribution and improve the performance of the worst class. Extensive experiments were conducted on the CIFAR-10, CIFAR-100, and STL-10 datasets, and the results demonstrate that our proposed method significantly enhances the robustness of the worst class, the accuracy of the worst class reaches 34.76% using the ResNet18 model on the CIFAR-10 dataset under A3 attack, with an average improvement of approximately 5% compared to existing methods. Meanwhile, the overall robustness reaches 48.47%, and the comprehensive metric ρrob based on TRADES reaches 0.55.
Related Concept Videos
Linear Approximation in Frequency Domain
In contrast, nonlinear systems do not inherently possess these properties. However, for small deviations around an operating point, a nonlinear system can often be approximated as linear.
IR Frequency Region: Fingerprint Region
The...
Determination of Expected Frequency
Expected Frequencies in Goodness-of-Fit Tests
Relative Frequency Distribution
Fast Fourier Transform
The computational efficiency of the FFT becomes...