Adversarial training with distribution normalization and margin balance

被引:9
|
作者
Cheng, Zhen [1 ,2 ]
Zhu, Fei [1 ,2 ]
Zhang, Xu-Yao [1 ,2 ]
Liu, Cheng-Lin [1 ,2 ]
机构
[1] Chinese Acad Sci, Natl Lab Pattern Recognit NLPR, Inst Automat, Beijing 100190, Peoples R China
[2] Univ Chinese Acad Sci UCAS, Sch Artificial Intelligence, Beijing 100049, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial robustness; Adversarial training; Distribution normalization; Margin balance;
D O I
10.1016/j.patcog.2022.109182
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training is the most effective method to improve adversarial robustness. However, it does not explicitly regularize the feature space during training. Adversarial attacks usually move a sample it-eratively along the direction which causes the steepest ascent of classification loss by crossing decision boundary. To alleviate this problem, we propose to regularize the distributions of different classes to increase the difficulty of finding an attacking direction. Specifically, we propose two strategies named Distribution Normalization (DN) and Margin Balance (MB) for adversarial training. The purpose of DN is to normalize the features of each class to have identical variance in every direction, in order to elimi-nate easy-to-attack intra-class directions. The purpose of MB is to balance the margins between different classes, making it harder to find confusing class directions (i.e., those with smaller margins) to attack. When integrated with adversarial training, our method can significantly improve adversarial robustness. Extensive experiments under white-box, black-box, and adaptive attacks demonstrate the effectiveness of our method over other state-of-the-art methods.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:11
相关论文
共 50 条
  • [1] Removing Batch Normalization Boosts Adversarial Training
    Wang, Haotao
    Zhang, Aston
    Zheng, Shuai
    Shi, Xingjian
    Li, Mu
    Wang, Zhangyang
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [2] Efficient Adversarial Defense without Adversarial Training: A Batch Normalization Approach
    Zhu, Yao
    Wei, Xiao
    Zhu, Yue
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [3] Increasing-Margin Adversarial (IMA) training to improve adversarial robustness of neural networks
    Ma, Linhai
    Liang, Liang
    COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2023, 240
  • [4] Global Wasserstein Margin maximization for boosting generalization in adversarial training
    Tingyue Yu
    Shen Wang
    Xiangzhan Yu
    Applied Intelligence, 2023, 53 : 11490 - 11504
  • [5] Boosting Adversarial Training with Learnable Distribution
    Chen, Kai
    Wang, Jinwei
    Adeke, James Msughter
    Liu, Guangjie
    Dai, Yuewei
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 78 (03): : 3247 - 3265
  • [6] Global Wasserstein Margin maximization for boosting generalization in adversarial training
    Yu, Tingyue
    Wang, Shen
    Yu, Xiangzhan
    APPLIED INTELLIGENCE, 2023, 53 (10) : 11490 - 11504
  • [7] Improving Robust Fairness via Balance Adversarial Training
    Sun, Chunyu
    Xu, Chenye
    Yao, Chengyuan
    Liang, Siyuan
    Wu, Yichao
    Liang, Ding
    Liu, Xianglong
    Liu, Aishan
    THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 12, 2023, : 15161 - 15169
  • [8] Adversarial Text Normalization
    Bitton, Joanna
    Pavlova, Maya
    Evtimov, Ivan
    2022 CONFERENCE OF THE NORTH AMERICAN CHAPTER OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, NAACL-HLT 2022, 2022, : 268 - 279
  • [9] Towards desirable decision boundary by Moderate-Margin Adversarial Training
    Liang, Xiaoyu
    Qian, Yaguan
    Huang, Jianchang
    Ling, Xiang
    Wang, Bin
    Wu, Chunming
    Swaileh, Wassim
    PATTERN RECOGNITION LETTERS, 2023, 173 : 30 - 37
  • [10] Spectral Normalization and Relativistic Adversarial Training for Conditional Pose Generation with Self-Attention
    Horiuchi, Yusuke
    Simo-Serra, Edgar
    Iizuka, Satoshi
    Ishikawa, Hiroshi
    PROCEEDINGS OF MVA 2019 16TH INTERNATIONAL CONFERENCE ON MACHINE VISION APPLICATIONS (MVA), 2019,