Images with incomplete attention regions vulnerable to attacks, new defense framework developed.
The study found that images with incomplete attention regions are more vulnerable to attacks, and successful attacks lead to scattered activation maps. To defend against attacks, the researchers designed a framework that preserves attention and rectifies model activation. This framework allows for better training and stronger attacks. The findings suggest that understanding visual attention changes can improve defense strategies against adversarial attacks.