Aug 2026· IEEE Transactions on Pattern Analysis and Machine Intelligence· Vol PP· 0 citations
Medicine
TL;DR
Deep Supervised Adversarial Robust Hashing (DSARH), an end-to-end framework that leverages similarity matrices and learnable hash codes to construct gradient-based worst-case perturbations, enabling efficient adversarial training and robust feature learning for retrieval, is proposed.
Abstract
Deep hashing has emerged as an effective and widely adopted framework for similarity retrieval, owing to its computational efficiency and the powerful feature extraction capabilities of deep learning (DL). Despite their strong performance in multi-modal and high-dimensional data retrieval tasks, recent studies have exposed the susceptibility of DL models to adversarial attacks, including in retrieval scenarios. This underscores the critical need for enhancing robustness in DL models to ensure reliable inference. However, most adversarial robustness studies focus on classification tasks, where explicit labels facilitate supervised adversarial training. In contrast, retrieval tasks typically rely on similarity matrices rather than explicit labels, making direct adversarial optimization challenging and limiting its application in large-scale retrieval settings. To address this gap, we propose Deep Supervised Adversarial Robust Hashing (DSARH), an end-to-end framework that leverages similarity matrices and learnable hash codes to construct gradient-based worst-case perturbations, enabling efficient adversarial training and robust feature learning for retrieval. Extensive experiments on cross-modal and image retrieval tasks demonstrate that existing deep hashing models are highly vulnerable to adversarial perturbations, whereas DSARH achieves superior robust generalization across a wide range of adversarial scenarios. Moreover, the robust visual features learned by DSARH help mitigate modality heterogeneity, resulting in consistent improvements in both standard and adversarial performance across multiple image-text retrieval benchmarks compared to state-of-the-art baselines. These results highlight the critical role of adversarial robustness in developing reliable and effective multi-modal retrieval systems.
UTDHA is proposed, the first unrestricted targeted attack for deep hashing models using contrastive-guided latent diffusion and outperforms existing targeted adversarial attack baselines for deep hashing models in both attack effectiveness and imperceptibility.
Fan Yang, Chuanchuan Ma, Yuhui Zheng et al.· Proceedings of the Thirty-Fi...· 0 citations
This study introduces an adversarial training optimization framework that incorporates hierarchical label encoding and prompt learning, designed to enhance model robustness and generalization in threat detection.
Yi-Qing Luo, Mingshu He, Xiao-Juan Wang· Proceedings of the Thirty-Fi...· 0 citations
Unrestricted Adversarial Examples (UAEs) pose a growing security challenge to Deep Neural Networks by introducing substantial, semantically natural modifications to images. While current diffusion-based methods improve the naturalness of UAEs, they suffer from two key limitations: an underutilization of the diffusion m...
Zhen-Zhao Pan, Xiao-Gang Zhang, Hua Chen et al.· IEEE Transactions on Pattern...· 0 citations
Extensive experiments demonstrate that IDATA consistently outperforms state-of-the-art baselines in attack success rate, memory efficiency, and visual imperceptibility, suggesting that IDATA is a promising tool for black-box robustness evaluation of deep visual models.
Yi Pan, Jun-Jie Huang, Tianrui Liu et al.· 0 citations
With face-recognition models now embedded in everyday authentication and surveillance, recent works have pinpointed a critical weakness: these models remain acutely vulnerable to adversarial semantic edits. I.e., adversarially produced semantic alterations to the input, such as slight aging or pose changes, can induce...
Ben Shapira, Roi Cohen, Shang-Tse Chen et al.· 0 citations
A novel energy-based optimization strategy to improve the robust generalization of machine learning models against adversarial attacks by incorporating the principles of energy-based models and shows strong and competitive performance across three extensively utilized datasets.