Robust Distillation via Untargeted and Targeted Intermediate Adversarial Samples

被引:1
|
作者
Dong, Junhao [1 ,2 ]
Koniusz, Piotr [3 ,4 ]
Chen, Junxi [5 ]
Wang, Z. Jane [6 ]
Ong, Yew-Soon [1 ,2 ]
机构
[1] Nanyang Technol Univ, Singapore, Singapore
[2] ASTAR, IHPC, CFAR, Singapore, Singapore
[3] Australian Natl Univ, Canberra, ACT, Australia
[4] Data61 CSIRO, Eveleigh, NSW, Australia
[5] Sun Yat Sen Univ, Guangzhou, Peoples R China
[6] Univ British Columbia, Vancouver, BC, Canada
基金
新加坡国家研究基金会;
关键词
D O I
10.1109/CVPR52733.2024.02686
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarially robust knowledge distillation aims to compress large-scale models into lightweight models while preserving adversarial robustness and natural performance on a given dataset. Existing methods typically align probability distributions of natural and adversarial samples between teacher and student models, but they overlook intermediate adversarial samples along the "adversarial path" formed by the multi-step gradient ascent of a sample towards the decision boundary. Such paths capture rich information about the decision boundary. In this paper, we propose a novel adversarially robust knowledge distillation approach by incorporating such adversarial paths into the alignment process. Recognizing the diverse impacts of intermediate adversarial samples (ranging from benign to noisy), we propose an adaptive weighting strategy to selectively emphasize informative adversarial samples, thus ensuring efficient utilization of lightweight model capacity. Moreover, we propose a dual-branch mechanism exploiting two following insights: (i) complementary dynamics of adversarial paths obtained by targeted and untargeted adversarial learning, and (ii) inherent differences between the gradient ascent path from class c(i) towards the nearest class boundary and the gradient descent path from a specific class c(j) towards the decision region of c(i) (i not equal j). Comprehensive experiments demonstrate the effectiveness of our method on lightweight models under various settings.
引用
收藏
页码:28432 / 28442
页数:11
相关论文
共 50 条
  • [41] Interpreting Robust Optimization via Adversarial Influence Functions
    Deng, Zhun
    Dwork, Cynthia
    Wang, Jialiang
    Zhang, Linjun
    25TH AMERICAS CONFERENCE ON INFORMATION SYSTEMS (AMCIS 2019), 2019,
  • [42] Robust anomaly detection via adversarial counterfactual generation
    Liguori, Angelica
    Ritacco, Ettore
    Pisani, Francesco Sergio
    Manco, Giuseppe
    KNOWLEDGE AND INFORMATION SYSTEMS, 2024, 66 (12) : 7437 - 7468
  • [43] Robust Market Making via Adversarial Reinforcement Learning
    Spooner, Thomas
    Savani, Rahul
    PROCEEDINGS OF THE TWENTY-NINTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2020, : 4590 - 4596
  • [44] Improving Robust Fairness via Balance Adversarial Training
    Sun, Chunyu
    Xu, Chenye
    Yao, Chengyuan
    Liang, Siyuan
    Wu, Yichao
    Liang, Ding
    Liu, Xianglong
    Liu, Aishan
    THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 12, 2023, : 15161 - 15169
  • [45] Indirect Adversarial Losses via an Intermediate Distribution for Training GANs
    Yang, Rui
    Duc Minh Vo
    Nakayama, Hideki
    2023 IEEE/CVF WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV), 2023, : 4641 - 4650
  • [46] Teacher-free Distillation via Regularizing Intermediate Representation
    Li, Lujun
    Liang, Shiuan-Ni
    Yang, Ya
    Jin, Zhe
    2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [47] Robust Pervasive Detection for Adversarial Samples of Artificial Intelligence in IoT Environments
    Wang, Shen
    Qiao, Zhuobiao
    IEEE ACCESS, 2019, 7 : 88693 - 88704
  • [48] Enhancing BERT Performance: Multi-teacher Adversarial Distillation with Clean and Robust Guidance
    Wu, Xunjin
    Chang, Jingfei
    Cheng, Wen
    Wu, Yunxiang
    Li, Yong
    Zeng, Lingfang
    CONCEPTUAL MODELING, ER 2024, 2025, 15238 : 3 - 17
  • [49] Robust Graph Neural Networks Against Adversarial Attacks via Jointly Adversarial Training
    Tian, Hu
    Ye, Bowei
    Zheng, Xiaolong
    Wu, Desheng Dash
    IFAC PAPERSONLINE, 2020, 53 (05): : 420 - 425
  • [50] Improved Quantitative Plant Proteomics via the Combination of Targeted and Untargeted Data Acquisition
    Hart-Smith, Gene
    Reis, Rodrigo S.
    Waterhouse, Peter M.
    Wilkins, Marc R.
    FRONTIERS IN PLANT SCIENCE, 2017, 8