Once-for-All Adversarial Training: In-Situ Tradeoff between Robustness and Accuracy for Free

被引:0
|
作者
Wang, Haotao [1 ]
Chen, Tianlong [1 ]
Gui, Shupeng [2 ]
Hu, Ting-Kuei [3 ]
Liu, Ji
Wang, Zhangyang [1 ,4 ]
机构
[1] Univ Texas Austin, Dept Elect & Comp Engn, Austin, TX 78712 USA
[2] Univ Rochester, Dept Comp Sci, Rochester, NY USA
[3] Texas A&M Univ, Dept Comp Sci & Engn, College Stn, TX USA
[4] Kwai Inc, Ytech Seattle Iab, FeDA Iab, AI Platform, Palo Alto, CA USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training and its many variants substantially improve deep network robustness, yet at the cost of compromising standard accuracy. Moreover, the training process is heavy and hence it becomes impractical to thoroughly explore the trade-off between accuracy and robustness. This paper asks this new question: how to quickly calibrate a trained model in-situ, to examine the achievable trade-offs between its standard and robust accuracies, without (re-)training it many times? Our proposed framework, Once-for-all Adversarial Training (OAT), is built on an innovative model-conditional training framework, with a controlling hyper-parameter as the input. The trained model could be adjusted among different standard and robust accuracies "for free" at testing time. As an important knob, we exploit dual batch normalization to separate standard and adversarial feature statistics, so that they can be learned in one model without degrading performance. We further extend OAT to a Once-for-all Adversarial Training and Slimming (OATS) framework, that allows for the joint trade-off among accuracy, robustness and runtime efficiency. Experiments show that, without any re-training nor ensembling, OAT/OATS achieve similar or even superior performance compared to dedicatedly trained models at various configurations. Our codes and pretrained models are available at: https://github.com/VITA-Group/Once-for-All-Adversarial-Training.
引用
收藏
页数:13
相关论文
共 32 条
  • [1] FLOAT: Fast Learnable Once-for-All Adversarial Training for Tunable Trade-off between Accuracy and Robustness
    Kundu, Souvik
    Sundaresan, Sairam
    Pedram, Massoud
    Beerel, Peter A.
    2023 IEEE/CVF WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV), 2023, : 2348 - 2357
  • [2] Does Interference Exist When Training a Once-For-All Network?
    Shipard, Jordan
    Wiliem, Arnold
    Fookes, Clinton
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS, CVPRW 2022, 2022, : 3618 - 3627
  • [3] Revisiting the Adversarial Robustness-Accuracy Tradeoff in Robot Learning
    Lechner, Mathias
    Amini, Alexander
    Rus, Daniela
    Henzinger, Thomas A.
    IEEE ROBOTICS AND AUTOMATION LETTERS, 2023, 8 (03) : 1595 - 1602
  • [4] Toward a Better Tradeoff Between Accuracy and Robustness for Image Classification via Adversarial Feature Diversity
    Xue, Wei
    Wang, Yonghao
    Wang, Yuchi
    Wang, Yue
    Du, Mingyang
    Zheng, Xiao
    IEEE Journal on Miniaturization for Air and Space Systems, 2024, 5 (04): : 254 - 264
  • [5] DetOFA: Efficient Training of Once-for-All Networks for Object Detection using Path Filter
    Sakuma, Yuiko
    Ishii, Masato
    Narihira, Takuya
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION WORKSHOPS, ICCVW, 2023, : 1325 - 1334
  • [6] Adversarial Finetuning with Latent Representation Constraint to Mitigate Accuracy-Robustness Tradeoff
    Suzuki, Satoshi
    Yamaguchi, Shin'ya
    Takeda, Shoichiro
    Kanai, Sekitoshi
    Makishima, Naoki
    Ando, Atsushi
    Masumura, Ryo
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4367 - 4378
  • [7] Robustness meets accuracy in adversarial training for graph autoencoder
    Zhou, Xianchen
    Hu, Kun
    Wang, Hongxia
    NEURAL NETWORKS, 2023, 157 : 114 - 124
  • [8] Towards Better Accuracy and Robustness with Localized Adversarial Training
    Rothberg, Eitan
    Chen, Tingting
    Ji, Hao
    THIRTY-THIRD AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FIRST INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE / NINTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2019, : 10017 - 10018
  • [9] ProX: A REVERSED ONCE-FOR-ALL NETWORK TRAINING PARADIGM FOR EFFICIENT EDGE MODELS TRAINING IN MEDICAL IMAGING
    Lim, Shin Wei
    Chan, Chee Seng
    Faizal, Erma Rahayu Mohd
    Ewe, Kok Howg
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 2211 - 2215
  • [10] GAAT: Group Adaptive Adversarial Training to Improve the Trade-Off Between Robustness and Accuracy
    Qian, Yaguan
    Liang, Xiaoyu
    Kang, Ming
    Wang, Bin
    Gu, Zhaoquan
    Wang, Xing
    Wu, Chunming
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2022, 36 (13)