Adversarial Information Bottleneck

被引:5
|
作者
Zhai, Penglong [1 ,2 ]
Zhang, Shihua [1 ,2 ]
机构
[1] Chinese Acad Sci, Acad Math & Syst Sci, Beijing 100190, Peoples R China
[2] Univ Chinese Acad Sci, Sch Math Sci, Beijing 100049, Peoples R China
基金
中国国家自然科学基金;
关键词
Robustness; Optimization; Mutual information; Deep learning; Perturbation methods; Training; Task analysis; Adversarial robustness; deep learning; hyperparameter selection; information bottleneck (IB);
D O I
10.1109/TNNLS.2022.3172986
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The information bottleneck (IB) principle has been adopted to explain deep learning in terms of information compression and prediction, which are balanced by a tradeoff hyperparameter. How to optimize the IB principle for better robustness and figure out the effects of compression through the tradeoff hyperparameter are two challenging problems. Previous methods attempted to optimize the IB principle by introducing random noise into learning the representation and achieved the state-of-the-art performance in the nuisance information compression and semantic information extraction. However, their performance on resisting adversarial perturbations is far less impressive. To this end, we propose an adversarial IB (AIB) method without any explicit assumptions about the underlying distribution of the representations, which can be optimized effectively by solving a min-max optimization problem. Numerical experiments on synthetic and real-world datasets demonstrate its effectiveness on learning more invariant representations and mitigating adversarial perturbations compared to several competing IB methods. In addition, we analyze the adversarial robustness of diverse IB methods contrasting with their IB curves and reveal that IB models with the hyperparameter beta corresponding to the knee point in the IB curve achieve the best tradeoff between compression and prediction and has the best robustness against various attacks.
引用
收藏
页码:221 / 230
页数:10
相关论文
共 50 条
  • [1] Enhancing Adversarial Transferability via Information Bottleneck Constraints
    Qi, Biqing
    Gao, Junqi
    Liu, Jianxing
    Wu, Ligang
    Zhou, Bowen
    IEEE SIGNAL PROCESSING LETTERS, 2024, 31 : 1414 - 1418
  • [2] Improving the Adversarial Robustness of NLP Models by Information Bottleneck
    Zhang, Cenyuan
    Zhou, Xiang
    Wan, Yixin
    Zheng, Xiaoqing
    Chang, Kai-Wei
    Hsieh, Cho-Jui
    FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (ACL 2022), 2022, : 3588 - 3598
  • [3] Improving Adversarial Robustness via Information Bottleneck Distillation
    Kuang, Huafeng
    Liu, Hong
    Wu, YongJian
    Satoh, Shin'ichi
    Ji, Rongrong
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [4] IB-RAR: Information Bottleneck as Regularizer for Adversarial Robustness
    Xu, Xiaoyun
    Perin, Guilherme
    Picek, Stjepan
    2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS, DSN-W, 2023, : 129 - 135
  • [5] InfoAT: Improving Adversarial Training Using the Information Bottleneck Principle
    Xu, Mengting
    Zhang, Tao
    Li, Zhongnian
    Zhang, Daoqiang
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (01) : 1255 - 1264
  • [6] Revisiting Hilbert-Schmidt Information Bottleneck for Adversarial Robustness
    Wang, Zifeng
    Jian, Tong
    Masoomi, Aria
    Ioannidis, Stratis
    Dy, Jennifer
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [7] Beyond Mutual Information: Generative Adversarial Network for Domain Adaptation Using Information Bottleneck Constraint
    Chen, Jiawei
    Zhang, Ziqi
    Xie, Xinpeng
    Li, Yuexiang
    Xu, Tao
    Ma, Kai
    Zheng, Yefeng
    IEEE TRANSACTIONS ON MEDICAL IMAGING, 2022, 41 (03) : 595 - 607
  • [8] Imitation Learning for Adaptive Video Streaming With Future Adversarial Information Bottleneck Principle
    Wang, Shuoyao
    Lin, Jiawei
    Ye, Fangwei
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (12) : 13670 - 13683
  • [9] Distilling Robust and Non-Robust Features in Adversarial Examples by Information Bottleneck
    Kim, Junho
    Lee, Byung-Kwan
    Ro, Yong Man
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [10] Robust Chinese Clinical Named Entity Recognition with information bottleneck and adversarial training
    He, Yunfei
    Zhang, Zhiqiang
    Shen, Jinlong
    Li, Yuling
    Zhang, Yiwen
    Ding, Weiping
    Yang, Fei
    APPLIED SOFT COMPUTING, 2024, 167