On the Generalization Properties of Adversarial Training

被引:0
|
作者
Xing, Yue [1 ]
Song, Qifan [1 ]
Cheng, Guang [1 ]
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Modern machine learning and deep learning models are shown to be vulnerable when testing data are slightly perturbed. Existing theoretical studies of adversarial training algorithms mostly focus on either adversarial training losses or local convergence properties. In contrast, this paper studies the generalization performance of a generic adversarial training algorithm. Specifically, we consider linear regression models and two-layer neural networks (with lazy training) using squared loss under low-dimensional and high-dimensional regimes. In the former regime, after overcoming the non-smoothness of adversarial training, the adversarial risk of the trained models can converge to the minimal adversarial risk. In the latter regime, we discover that data interpolation prevents the adversarially robust estimator from being consistent. Therefore, inspired by successes of the least absolute shrinkage and selection operator (LASSO), we incorporate the L-1 penalty in the high dimensional adversarial learning and show that it leads to consistent adversarially robust estimation. A series of numerical studies are conducted to demonstrate how the smoothness and L-1 penalization help improve the adversarial robustness of DNN models.
引用
收藏
页码:505 / +
页数:10
相关论文
共 50 条
  • [21] On the Generalization Analysis of Adversarial Learning
    Mustafa, Waleed
    Lei, Yunwen
    Kloft, Marius
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [22] Disentangling Adversarial Robustness and Generalization
    Stutz, David
    Hein, Matthias
    Schiele, Bernt
    [J]. 2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, : 6969 - 6980
  • [23] Decomposed adversarial domain generalization
    Chen, Sentao
    [J]. KNOWLEDGE-BASED SYSTEMS, 2023, 263
  • [24] The benefits of adversarial defense in generalization
    Oneto, Luca
    Ridella, Sandro
    Anguita, Davide
    [J]. NEUROCOMPUTING, 2022, 505 : 125 - 141
  • [25] Localized Adversarial Domain Generalization
    Zhu, Wei
    Lu, Le
    Xiao, Jing
    Han, Mei
    Luo, Jiebo
    Harrison, Adam P.
    [J]. 2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 7098 - 7108
  • [26] Generalization analysis of adversarial pairwise learning
    Wen, Wen
    Li, Han
    Wu, Rui
    Wu, Lingjuan
    Chen, Hong
    [J]. Neural Networks, 2025, 183
  • [27] On the Role of Generalization in Transferability of Adversarial Examples
    Wang, Yilin
    Farnia, Farzan
    [J]. UNCERTAINTY IN ARTIFICIAL INTELLIGENCE, 2023, 216 : 2259 - 2270
  • [28] Privacy protection generalization with adversarial fusion
    Wang, Hao
    Sun, Guangmin
    Zheng, Kun
    Li, Hui
    Liu, Jie
    Bai, Yu
    [J]. MATHEMATICAL BIOSCIENCES AND ENGINEERING, 2022, 19 (07) : 7314 - 7336
  • [29] Aliasing and adversarial robust generalization of CNNs
    Julia Grabinski
    Janis Keuper
    Margret Keuper
    [J]. Machine Learning, 2022, 111 : 3925 - 3951
  • [30] Adversarial data splitting for domain generalization
    Gu, Xiang
    Sun, Jian
    Xu, Zongben
    [J]. SCIENCE CHINA-INFORMATION SCIENCES, 2024, 67 (05)