Boosting Accuracy and Robustness of Student Models via Adaptive Adversarial Distillation

被引:10
|
作者
Huang, Bo [1 ,2 ]
Chen, Mingyang [1 ,2 ]
Wang, Yi [3 ]
Lu, Junda [4 ]
Cheng, Minhao [2 ]
Wang, Wei [1 ,2 ]
机构
[1] Hong Kong Univ Sci & Technol Guangzhou, Guangzhou, Peoples R China
[2] Hong Kong Univ Sci & Technol, Hong Kong, Peoples R China
[3] Dongguan Univ Technol, Dongguan, Peoples R China
[4] Macquarie Univ, Sydney, NSW, Australia
关键词
D O I
10.1109/CVPR52729.2023.02363
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Distilled student models in teacher-student architectures are widely considered for computational-effective deployment in real-time applications and edge devices. However, there is a higher risk of student models to encounter adversarial attacks at the edge. Popular enhancing schemes such as adversarial training have limited performance on compressed networks. Thus, recent studies concern about adversarial distillation (AD) that aims to inherit not only prediction accuracy but also adversarial robustness of a robust teacher model under the paradigm of robust optimization. In the min-max framework of AD, existing AD methods generally use fixed supervision information from the teacher model to guide the inner optimization for knowledge distillation which often leads to an overcorrection towards model smoothness. In this paper, we propose an adaptive adversarial distillation (AdaAD) that involves the teacher model in the knowledge optimization process in a way interacting with the student model to adaptively search for the inner results. Comparing with state-of-the-art methods, the proposed AdaAD can significantly boost both the prediction accuracy and adversarial robustness of student models in most scenarios. In particular, the ResNet-18 model trained by AdaAD achieves top-rank performance (54.23% robust accuracy) on RobustBench under AutoAttack.
引用
收藏
页码:24668 / 24677
页数:10
相关论文
共 50 条
  • [31] Adversarial robustness via attention transfer
    Li, Zhuorong
    Feng, Chao
    Wu, Minghui
    Yu, Hongchuan
    Zheng, Jianwei
    Zhu, Fanwei
    PATTERN RECOGNITION LETTERS, 2021, 146 : 172 - 178
  • [32] Achieving adversarial robustness via sparsity
    Liao, Ningyi
    Wang, Shufan
    Xiang, Liyao
    Ye, Nanyang
    Shao, Shuo
    Chu, Pengzhi
    MACHINE LEARNING, 2022, 111 (02) : 685 - 711
  • [33] Impartial Adversarial Distillation: Addressing Biased Data-Free Knowledge Distillation via Adaptive Constrained Optimization
    Liao, Donping
    Gao, Xitong
    Xu, Chengzhong
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 4, 2024, : 3342 - 3350
  • [34] Revisiting Adversarial Robustness Distillation from the Perspective of Robust Fairness
    Yue, Xinli
    Mou, Ningping
    Wang, Qian
    Zhao, Lingchen
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [35] Achieving adversarial robustness via sparsity
    Ningyi Liao
    Shufan Wang
    Liyao Xiang
    Nanyang Ye
    Shuo Shao
    Pengzhi Chu
    Machine Learning, 2022, 111 : 685 - 711
  • [36] Enhancing Adversarial Robustness in Low-Label Regime via Adaptively Weighted Regularization and Knowledge Distillation
    Yang, Dongyoon
    Kong, Insung
    Kim, Yongdai
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4529 - 4538
  • [37] Enhancing Noise Robustness of Retrieval-Augmented Language Models with Adaptive Adversarial Training
    Fang, Feiteng
    Bai, Yuelin
    Ni, Shiwen
    Yang, Min
    Chen, Xiaojun
    Xu, Ruifeng
    PROCEEDINGS OF THE 62ND ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, VOL 1: LONG PAPERS, 2024, : 10028 - 10039
  • [38] INTELLIGENT AND ADAPTIVE MIXUP TECHNIQUE FOR ADVERSARIAL ROBUSTNESS
    Agarwal, Akshay
    Vatsa, Mayank
    Singh, Richa
    Ratha, Nalini
    2021 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2021, : 824 - 828
  • [39] Adaptive Batch Normalization Networks for Adversarial Robustness
    Lo, Shao-Yuan
    Patel, Vishal M.
    2024 IEEE INTERNATIONAL CONFERENCE ON ADVANCED VIDEO AND SIGNAL BASED SURVEILLANCE, AVSS 2024, 2024,
  • [40] Improving Adversarial Robustness via Attention and Adversarial Logit Pairing
    Li, Xingjian
    Goodman, Dou
    Liu, Ji
    Wei, Tao
    Dou, Dejing
    FRONTIERS IN ARTIFICIAL INTELLIGENCE, 2022, 4