login

Proceedings of the 29th ACM International Conference on Multimedia

Published 17 October 2021Open access
Jiutao Yue, Haofeng Li, Pengxu Wei, Guanbin Li, Liang Lin
Citations922
View PDF

TL;DR

A robust deep learning framework for real-world SR that randomly erases potential adversarial noises in the frequency domain of input images or features and is more insensitive to adversarial attacks and presents more stable SR results than existing models and defenses is proposed.

Abstract

Recently deep neural networks (DNNs) have achieved significant success in\nreal-world image super-resolution (SR). However, adversarial image samples with\nquasi-imperceptible noises could threaten deep learning SR models. In this\npaper, we propose a robust deep learning framework for real-world SR that\nrandomly erases potential adversarial noises in the frequency domain of input\nimages or features. The rationale is that on the SR task clean images or\nfeatures have a different pattern from the attacked ones in the frequency\ndomain. Observing that existing adversarial attacks usually add high-frequency\nnoises to input images, we introduce a novel random frequency mask module that\nblocks out high-frequency components possibly containing the harmful\nperturbations in a stochastic manner. Since the frequency masking may not only\ndestroys the adversarial perturbations but also affects the sharp details in a\nclean image, we further develop an adversarial sample classifier based on the\nfrequency domain of images to determine if applying the proposed mask module.\nBased on the above ideas, we devise a novel real-world image SR framework that\ncombines the proposed frequency mask modules and the proposed adversarial\nclassifier with an existing super-resolution backbone network. Experiments show\nthat our proposed method is more insensitive to adversarial attacks and\npresents more stable SR results than existing models and defenses.\n

Keywords

Computer Science