科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ Scientific Reports2026-05-02· Adversarial system

Hybrid reverse knowledge distillation for adversarial example detection

Hyun Kwon, Joo Bon Maeng, Dae-Jin Kim

原始摘要(英文原文)· Original abstract
Deep neural networks have achieved remarkable success in various computer vision tasks, yet they remain vulnerable to adversarial examples-carefully crafted perturbations that are imperceptible to humans but cause misclassification. Detecting such adversarial inputs is crucial for deploying reliable AI systems, particularly in safety-critical applications such as medical diagnosis and autonomous driving. In this paper, we propose a novel adversarial detection method based on Hybrid Reverse Knowledge Distillation (Hybrid RKD). Our approach trains a multi-scale decoder to reconstruct intermediate feature representations of a frozen teacher encoder using only clean images. The key insight is that adversarial perturbations cause feature-level distortions that the decoder, trained exclusively on normal data, cannot accurately reconstruct. We further enhance detection performance by incorporating Mahalanobis-style statistical distance metrics that capture distribution-level anomalies. Extensive experiments on CIFAR-10 and ISIC2018 datasets demonstrate that our method achieves state-of-the-art detection performance against various adversarial attacks including FGSM, PGD, DeepFool, C&W, and AutoAttack, with average AUROC scores of 0.790 and 0.929 across five attack categories, respectively. Our hybrid approach consistently outperforms existing detection methods including LID, Mahalanobis, and ODIN, while requiring no adversarial examples during training.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Hybrid reverse knowledge distillation for adversarial example detection — 科研速览 Science Skim