The Enemy of My Enemy is My Friend: Exploring Inverse Adversaries for Improving Adversarial Training

被引:7
|
作者
Dong, Junhao [1 ]
Moosavi-Dezfooli, Seyed-Mohsen [2 ]
Lai, Jianhuang [1 ,3 ,4 ]
Xie, Xiaohua [1 ,3 ,4 ]
机构
[1] Sun Yat Sen Univ, Sch Comp Sci & Engn, Guangzhou, Peoples R China
[2] Imperial Coll London, London, England
[3] Guangdong Prov Key Lab Informat Secur Technol, Guangzhou, Peoples R China
[4] Minist Educ, Key Lab Machine Intelligence & Adv Comp, Beijing, Peoples R China
关键词
D O I
10.1109/CVPR52729.2023.02364
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Although current deep learning techniques have yielded superior performance on various computer vision tasks, yet they are still vulnerable to adversarial examples. Adversarial training and its variants have been shown to be the most effective approaches to defend against adversarial examples. A particular class of these methods regularize the difference between output probabilities for an adversarial and its corresponding natural example. However, it may have a negative impact if a natural example is misclassified. To circumvent this issue, we propose a novel adversarial training scheme that encourages the model to produce similar output probabilities for an adversarial example and its "inverse adversarial" counterpart. Particularly, the counterpart is generated by maximizing the likelihood in the neighborhood of the natural example. Extensive experiments on various vision datasets and architectures demonstrate that our training method achieves state-of-the-art robustness as well as natural accuracy among robust models. Furthermore, using a universal version of inverse adversarial examples, we improve the performance of single-step adversarial training techniques at a low computational cost.
引用
收藏
页码:24678 / 24687
页数:10
相关论文
共 50 条
  • [31] Editorial overview: Microbe-microbe interactions: the enemy of my enemy is my friend
    Skaar, Eric P.
    Zackular, Joseph P.
    CURRENT OPINION IN MICROBIOLOGY, 2020, 53 : III - V
  • [32] MY FRIEND, THE ENEMY - AVNERY,U
    BARRON, A
    JOURNAL OF PALESTINE STUDIES, 1988, 18 (01) : 228 - 230
  • [33] MY FRIEND, THE ENEMY - AVNERY,U
    PERETZ, D
    MIDDLE EAST JOURNAL, 1987, 41 (02): : 295 - 296
  • [34] MY FRIEND THE ENEMY - AVNERY,U
    NAKHLEH, K
    MUSLIM WORLD, 1989, 79 (3-4): : 249 - 250
  • [35] The enemy of my enemy
    Deane, Caitlin
    NATURE CHEMICAL BIOLOGY, 2021, 17 (02) : 123 - 123
  • [36] The Enemy of My Enemy Is Not My Friend: Arabic Twitter Sentiment toward ISIS and the United States
    Romney, David
    Jamal, Amaney A.
    Keohane, Robert O.
    Tingley, Dustin
    INTERNATIONAL STUDIES QUARTERLY, 2021, 65 (04) : 1176 - 1184
  • [37] Enemy of my enemy
    Swibel, M
    FORBES, 2005, 176 (10): : 58 - 58
  • [38] Enemy of my enemy
    Rukavishnikov, VO
    SOTSIOLOGICHESKIE ISSLEDOVANIYA, 2005, (05): : 30 - +
  • [39] The enemy of my enemy
    Caitlin Deane
    Nature Chemical Biology, 2021, 17 : 123 - 123
  • [40] Ecology - The enemy of my enemy is my ally
    Sabelis, MW
    Janssen, A
    Kant, MR
    SCIENCE, 2001, 291 (5511) : 2104 - 2105