Robust Distillation via Untargeted and Targeted Intermediate Adversarial Samples

被引:1
|
作者
Dong, Junhao [1 ,2 ]
Koniusz, Piotr [3 ,4 ]
Chen, Junxi [5 ]
Wang, Z. Jane [6 ]
Ong, Yew-Soon [1 ,2 ]
机构
[1] Nanyang Technol Univ, Singapore, Singapore
[2] ASTAR, IHPC, CFAR, Singapore, Singapore
[3] Australian Natl Univ, Canberra, ACT, Australia
[4] Data61 CSIRO, Eveleigh, NSW, Australia
[5] Sun Yat Sen Univ, Guangzhou, Peoples R China
[6] Univ British Columbia, Vancouver, BC, Canada
基金
新加坡国家研究基金会;
关键词
D O I
10.1109/CVPR52733.2024.02686
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarially robust knowledge distillation aims to compress large-scale models into lightweight models while preserving adversarial robustness and natural performance on a given dataset. Existing methods typically align probability distributions of natural and adversarial samples between teacher and student models, but they overlook intermediate adversarial samples along the "adversarial path" formed by the multi-step gradient ascent of a sample towards the decision boundary. Such paths capture rich information about the decision boundary. In this paper, we propose a novel adversarially robust knowledge distillation approach by incorporating such adversarial paths into the alignment process. Recognizing the diverse impacts of intermediate adversarial samples (ranging from benign to noisy), we propose an adaptive weighting strategy to selectively emphasize informative adversarial samples, thus ensuring efficient utilization of lightweight model capacity. Moreover, we propose a dual-branch mechanism exploiting two following insights: (i) complementary dynamics of adversarial paths obtained by targeted and untargeted adversarial learning, and (ii) inherent differences between the gradient ascent path from class c(i) towards the nearest class boundary and the gradient descent path from a specific class c(j) towards the decision region of c(i) (i not equal j). Comprehensive experiments demonstrate the effectiveness of our method on lightweight models under various settings.
引用
收藏
页码:28432 / 28442
页数:11
相关论文
共 50 条
  • [31] Learning Differentially Private Diffusion Models via Stochastic Adversarial Distillation
    Liu, Bochao
    Wang, Pengju
    Ge, Shiming
    COMPUTER VISION-ECCV 2024, PT VII, 2025, 15065 : 55 - 71
  • [32] Targeted and untargeted quantification of quorum sensing signalling molecules in bacterial cultures and biological samples via HPLC-TQ MS techniques
    Federica Dal Bello
    Michael Zorzi
    Riccardo Aigotti
    Davide Medica
    Vito Fanelli
    Vincenzo Cantaluppi
    Eleonora Amante
    Viviana Teresa Orlandi
    Claudio Medana
    Analytical and Bioanalytical Chemistry, 2021, 413 : 853 - 864
  • [33] CAD : Photorealistic 3D Generation via Adversarial Distillation
    Wan, Ziyu
    Paschalidou, Despoina
    Huang, Ian
    Liu, Hongyu
    Shen, Bokui
    Xiang, Xiaoyu
    Liao, Jing
    Guibas, Leonidas
    Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition, 2024, : 10194 - 10207
  • [34] Targeted and untargeted quantification of quorum sensing signalling molecules in bacterial cultures and biological samples via HPLC-TQ MS techniques
    Dal Bello, Federica
    Zorzi, Michael
    Aigotti, Riccardo
    Medica, Davide
    Fanelli, Vito
    Cantaluppi, Vincenzo
    Amante, Eleonora
    Orlandi, Viviana Teresa
    Medana, Claudio
    ANALYTICAL AND BIOANALYTICAL CHEMISTRY, 2021, 413 (03) : 853 - 864
  • [35] Robust and Accurate Object Detection via Adversarial Learning
    Chen, Xiangning
    Xie, Cihang
    Tan, Mingxing
    Zhang, Li
    Hsieh, Cho-Jui
    Gong, Boqing
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 16617 - 16626
  • [36] Robust quantum classifiers via NISQ adversarial learning
    Leonardo Banchi
    Nature Computational Science, 2022, 2 : 699 - 700
  • [37] Enhancing Adversarial Robustness via Stochastic Robust Framework
    Sun, Zhenjiang
    Li, Yuanbo
    Hu, Cong
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT IV, 2024, 14428 : 187 - 198
  • [38] Interpreting Robust Optimization via Adversarial Influence Functions
    Deng, Zhun
    Dwork, Cynthia
    Wang, Jialiang
    Zhang, Linjun
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 119, 2020, 119
  • [39] Robust quantum classifiers via NISQ adversarial learning
    Banchi, Leonardo
    NATURE COMPUTATIONAL SCIENCE, 2022, 2 (11): : 699 - 700
  • [40] Adversarial robustness via robust low rank representations
    Awasthi, Pranjal
    Jain, Himanshu
    Rawat, Ankit Singh
    Vijayaraghavan, Aravindan
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS (NEURIPS 2020), 2020, 33