Regional Adversarial Training for Better Robust Generalization

被引:0
|
作者
Song, Chuanbiao [1 ]
Fan, Yanbo [2 ]
Zhou, Aoyang [1 ]
Wu, Baoyuan [3 ,4 ]
Li, Yiming [5 ]
Li, Zhifeng [2 ]
He, Kun [1 ]
机构
[1] Huazhong Univ Sci & Technol, Wuhan, Hubei, Peoples R China
[2] Tencent, Shenzhen, Guangdong, Peoples R China
[3] Chinese Univ Hong Kong, Shenzhen, Guangdong, Peoples R China
[4] Shenzhen Res Inst Big Data, Shenzhen, Guangdong, Peoples R China
[5] Tsinghua Univ, Beijing, Peoples R China
基金
中国国家自然科学基金; 美国国家科学基金会;
关键词
Regional Adversarial Training; Robustness; Adversarial Defense; Label Smoothing;
D O I
10.1007/s11263-024-02103-w
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training (AT) has been demonstrated as one of the most promising defense methods against various adversarial attacks. To our knowledge, existing AT-based methods usually train with the locally most adversarial perturbed points and treat all the perturbed points equally, which may lead to considerably weaker adversarial robust generalization on test data. In this work, we introduce a new adversarial training framework that considers the diversity as well as characteristics of the perturbed points in the vicinity of benign samples. To realize the framework, we propose a Regional Adversarial Training (RAT) defense method that first utilizes the attack path generated by the typical iterative attack method of projected gradient descent (PGD), and constructs an adversarial region based on the attack path. Then, RAT samples diverse perturbed training points efficiently inside this region, and utilizes a distance-aware label smoothing mechanism to capture our intuition that perturbed points at different locations should have different impact on the model performance. Extensive experiments on several benchmark datasets show that RAT consistently makes significant improvement on standard adversarial training (SAT), and exhibits better robust generalization.
引用
收藏
页码:4510 / 4520
页数:11
相关论文
共 50 条
  • [1] Adversarial Vertex Mixup: Toward Better Adversarially Robust Generalization
    Lee, Saehyung
    Lee, Hyungyu
    Yoon, Sungroh
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2020, : 269 - 278
  • [2] Inter-feature Relationship Certifies Robust Generalization of Adversarial Training
    Zhang, Shufei
    Qian, Zhuang
    Huang, Kaizhu
    Wang, Qiu-Feng
    Gu, Bin
    Xiong, Huan
    Yi, Xinping
    INTERNATIONAL JOURNAL OF COMPUTER VISION, 2024, : 5565 - 5581
  • [3] On the Generalization Properties of Adversarial Training
    Xing, Yue
    Song, Qifan
    Cheng, Guang
    24TH INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS (AISTATS), 2021, 130 : 505 - +
  • [4] Improving Generalization of Adversarial Training via Robust Critical Fine-Tuning
    Zhu, Kaijie
    Hu, Xixu
    Wang, Jindong
    Xie, Xing
    Yang, Ge
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4401 - 4411
  • [5] Aliasing and adversarial robust generalization of CNNs
    Julia Grabinski
    Janis Keuper
    Margret Keuper
    Machine Learning, 2022, 111 : 3925 - 3951
  • [6] Aliasing and adversarial robust generalization of CNNs
    Grabinski, Julia
    Keuper, Janis
    Keuper, Margret
    MACHINE LEARNING, 2022, 111 (11) : 3925 - 3951
  • [7] On Generalization of Graph Autoencoders with Adversarial Training
    Huang, Tianjin
    Pei, Yulong
    Menkovski, Vlado
    Pechenizkiy, Mykola
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2021: RESEARCH TRACK, PT II, 2021, 12976 : 367 - 382
  • [8] THE CURSE OF OVERPARAMETRIZATION IN ADVERSARIAL TRAINING: PRECISE ANALYSIS OF ROBUST GENERALIZATION FOR RANDOM FEATURES REGRESSION
    Hassani, Hamed
    Javanmard, Adel
    ANNALS OF STATISTICS, 2024, 52 (02): : 441 - 465
  • [9] Towards Better Understanding of Training Certifiably Robust Models against Adversarial Examples
    Lee, Sungyoon
    Lee, Woojin
    Park, Jinseong
    Lee, Jaewook
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021,
  • [10] Adversarial Weight Perturbation Helps Robust Generalization
    Wu, Dongxian
    Xia, Shu-Tao
    Wang, Yisen
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS (NEURIPS 2020), 2020, 33