Papers › Feature Denoising for Improving Adversarial Robustness

Feature Denoising for Improving Adversarial Robustness

9 Dec 2018CVPR 2019 6arXiv:1812.03411archive 2025-07-28

Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan Yuille, Kaiming He

Adversarial attacks to image classification systems present challenges to convolutional networks and opportunities for understanding them. This study suggests that adversarial perturbations on images lead to noise in the features constructed by these networks. Motivated by this observation, we develop new network architectures that increase adversarial robustness by performing feature denoising. Specifically, our networks contain blocks that denoise the features using non-local means or other filters; the entire networks are trained end-to-end. When combined with adversarial training, our feature denoising networks substantially improve the state-of-the-art in adversarial robustness in both white-box and black-box attack settings. On ImageNet, under 10-iteration PGD white-box attacks where prior art has 27.9% accuracy, our method achieves 55.7%; even under extreme 2000-iteration PGD white-box attacks, our method secures 42.6% accuracy. Our method was ranked first in Competition on Adversarial Attacks and Defenses (CAAD) 2018 --- it achieved 50.6% classification accuracy on a secret, ImageNet-like test dataset against 48 unknown attackers, surpassing the runner-up approach by ~10%. Code is available at https://github.com/facebookresearch/ImageNet-Adversarial-Training.

PaperPDFConference PDFCode

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

Code

facebookresearch/ImageNet-Adversarial-Training officialmentioned in papermentioned on GitHubtfNOASSERTION report
lirundong/quant-pack mentioned on GitHubpytorchNOASSERTION report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

Adversarial DefenseAdversarial RobustnessGeneral ClassificationImage Classificationimage-classification

Results from the paper archive 2025-07-28

TaskDatasetModelMetricValueRank at snapshotLeaderboardReport
Adversarial Defense CAAD 2018 Feature Denoising Accuracy 50.6% #1 of 1 Archive leaderboard report
Adversarial Defense ImageNet Feature Denoising Accuracy 49.5% #3 of 3 Archive leaderboard report
Adversarial Defense ImageNet (targeted PGD, max perturbation=16) ResNet-152 Denoise Accuracy 42.8 #1 of 3 Archive leaderboard report
Adversarial Defense ImageNet (targeted PGD, max perturbation=16) ResNeXt-101 DenoiseAll Accuracy 40.4 #2 of 3 Archive leaderboard report
Adversarial Defense ImageNet (targeted PGD, max perturbation=16) ResNet-152 Accuracy 39.0 #3 of 3 Archive leaderboard report

Ranks are positions in the archive's leaderboards as they stood at the 2025-07-28 snapshot. Results published since then are not among these rows, so a rank here is not a current standing.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections