Regional Adversarial Training for Better Robust Generalization

被引:0
|
作者
Song, Chuanbiao [1 ]
Fan, Yanbo [2 ]
Zhou, Aoyang [1 ]
Wu, Baoyuan [3 ,4 ]
Li, Yiming [5 ]
Li, Zhifeng [2 ]
He, Kun [1 ]
机构
[1] Huazhong Univ Sci & Technol, Wuhan, Hubei, Peoples R China
[2] Tencent, Shenzhen, Guangdong, Peoples R China
[3] Chinese Univ Hong Kong, Shenzhen, Guangdong, Peoples R China
[4] Shenzhen Res Inst Big Data, Shenzhen, Guangdong, Peoples R China
[5] Tsinghua Univ, Beijing, Peoples R China
基金
中国国家自然科学基金; 美国国家科学基金会;
关键词
Regional Adversarial Training; Robustness; Adversarial Defense; Label Smoothing;
D O I
10.1007/s11263-024-02103-w
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training (AT) has been demonstrated as one of the most promising defense methods against various adversarial attacks. To our knowledge, existing AT-based methods usually train with the locally most adversarial perturbed points and treat all the perturbed points equally, which may lead to considerably weaker adversarial robust generalization on test data. In this work, we introduce a new adversarial training framework that considers the diversity as well as characteristics of the perturbed points in the vicinity of benign samples. To realize the framework, we propose a Regional Adversarial Training (RAT) defense method that first utilizes the attack path generated by the typical iterative attack method of projected gradient descent (PGD), and constructs an adversarial region based on the attack path. Then, RAT samples diverse perturbed training points efficiently inside this region, and utilizes a distance-aware label smoothing mechanism to capture our intuition that perturbed points at different locations should have different impact on the model performance. Extensive experiments on several benchmark datasets show that RAT consistently makes significant improvement on standard adversarial training (SAT), and exhibits better robust generalization.
引用
收藏
页码:4510 / 4520
页数:11
相关论文
共 50 条
  • [41] ATGAN: Adversarial training-based GAN for improving adversarial robustness generalization on image classification
    Desheng Wang
    Weidong Jin
    Yunpu Wu
    Aamir Khan
    Applied Intelligence, 2023, 53 : 24492 - 24508
  • [42] ATGAN: Adversarial training-based GAN for improving adversarial robustness generalization on image classification
    Wang, Desheng
    Jin, Weidong
    Wu, Yunpu
    Khan, Aamir
    APPLIED INTELLIGENCE, 2023, 53 (20) : 24492 - 24508
  • [43] Reinforcement Based Learning on Classification Task Yields Better Generalization and Adversarial Accuracy
    Gupta, Shashi Kant
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 15793 - 15794
  • [44] SafeAMC: Adversarial training for robust modulation classification models
    Maroto, Javier
    Bovet, Gerome
    Frossard, Pascal
    2022 30TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO 2022), 2022, : 1636 - 1640
  • [45] Adversarial Training Towards Robust Multimedia Recommender System
    Tang, Jinhui
    Du, Xiaoyu
    He, Xiangnan
    Yuan, Fajie
    Tian, Qi
    Chua, Tat-Seng
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2020, 32 (05) : 855 - 867
  • [46] Training Augmentation with Adversarial Examples for Robust Speech Recognition
    Sun, Sining
    Yeh, Ching-Feng
    Ostendorf, Mari
    Hwang, Mei-Yuh
    Xie, Lei
    19TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2018), VOLS 1-6: SPEECH RESEARCH FOR EMERGING MARKETS IN MULTILINGUAL SOCIETIES, 2018, : 2404 - 2408
  • [47] Robust Training with Feature-Based Adversarial Example
    Fu, Xuanming
    Yang, Zhengfeng
    Xue, Hao
    Wang, Jianlin
    Zeng, Zhenbing
    2022 26TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2022, : 2957 - 2963
  • [48] Better generalization with less data using robust gradient descent
    Holland, Matthew J.
    Ikeda, Kazushi
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97
  • [49] Supervised contrastive learning for robust text adversarial training
    Li, Weidong
    Zhao, Bo
    An, Yang
    Shangguan, Chenhan
    Ji, Minzi
    Yuan, Anqi
    NEURAL COMPUTING & APPLICATIONS, 2023, 35 (10): : 7357 - 7368
  • [50] Robust Pre-Training by Adversarial Contrastive Learning
    Jiang, Ziyu
    Chen, Tianlong
    Chen, Ting
    Wang, Zhangyang
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33