Adversarial training with distribution normalization and margin balance

被引:9
|
作者
Cheng, Zhen [1 ,2 ]
Zhu, Fei [1 ,2 ]
Zhang, Xu-Yao [1 ,2 ]
Liu, Cheng-Lin [1 ,2 ]
机构
[1] Chinese Acad Sci, Natl Lab Pattern Recognit NLPR, Inst Automat, Beijing 100190, Peoples R China
[2] Univ Chinese Acad Sci UCAS, Sch Artificial Intelligence, Beijing 100049, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial robustness; Adversarial training; Distribution normalization; Margin balance;
D O I
10.1016/j.patcog.2022.109182
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training is the most effective method to improve adversarial robustness. However, it does not explicitly regularize the feature space during training. Adversarial attacks usually move a sample it-eratively along the direction which causes the steepest ascent of classification loss by crossing decision boundary. To alleviate this problem, we propose to regularize the distributions of different classes to increase the difficulty of finding an attacking direction. Specifically, we propose two strategies named Distribution Normalization (DN) and Margin Balance (MB) for adversarial training. The purpose of DN is to normalize the features of each class to have identical variance in every direction, in order to elimi-nate easy-to-attack intra-class directions. The purpose of MB is to balance the margins between different classes, making it harder to find confusing class directions (i.e., those with smaller margins) to attack. When integrated with adversarial training, our method can significantly improve adversarial robustness. Extensive experiments under white-box, black-box, and adaptive attacks demonstrate the effectiveness of our method over other state-of-the-art methods.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:11
相关论文
共 50 条
  • [21] Advancing diagnostic performance and clinical usability of neural networks via adversarial training and dual batch normalization
    Tianyu Han
    Sven Nebelung
    Federico Pedersoli
    Markus Zimmermann
    Maximilian Schulze-Hagen
    Michael Ho
    Christoph Haarburger
    Fabian Kiessling
    Christiane Kuhl
    Volkmar Schulz
    Daniel Truhn
    Nature Communications, 12
  • [22] Modeling Adversarial Noise for Adversarial Training
    Zhou, Dawei
    Wang, Nannan
    Han, Bo
    Liu, Tongliang
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [23] DSRM: Boost Textual Adversarial Training with Distribution Shift Risk Minimization
    Gao, Songyang
    Dou, Shihan
    Liu, Yan
    Wang, Xiao
    Zhang, Qi
    Wei, Zhongyu
    Ma, Jin
    Shan, Ying
    PROCEEDINGS OF THE 61ST ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (ACL 2023): LONG PAPERS, VOL 1, 2023, : 12177 - 12189
  • [24] Adversarial Training for Privacy-Preserving Deep Learning Model Distribution
    Alawad, Mohammed
    Gao, Shang
    Wu, Xiao-Cheng
    Durbin, Eric B.
    Coyle, Linda
    Penberthy, Lynne
    Tourassi, Georgia
    2019 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2019, : 5705 - 5710
  • [25] Improving Out-of-Distribution Generalization by Adversarial Training with Structured Priors
    Wang, Qixun
    Wang, Yifei
    Zhu, Hong
    Wang, Yisen
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [26] ADVERSARIAL NORMALIZATION FOR MULTI DOMAIN IMAGE SEGMENTATION
    Delisle, Pierre-Luc
    Anctil-Robitaille, Benoit
    Desrosiers, Christian
    Lombaert, Nerve
    2020 IEEE 17TH INTERNATIONAL SYMPOSIUM ON BIOMEDICAL IMAGING (ISBI 2020), 2020, : 849 - 853
  • [27] Adaptive Batch Normalization Networks for Adversarial Robustness
    Lo, Shao-Yuan
    Patel, Vishal M.
    2024 IEEE INTERNATIONAL CONFERENCE ON ADVANCED VIDEO AND SIGNAL BASED SURVEILLANCE, AVSS 2024, 2024,
  • [28] Recent Advances in Adversarial Training for Adversarial Robustness
    Bai, Tao
    Luo, Jinqi
    Zhao, Jun
    Wen, Bihan
    Wang, Qian
    PROCEEDINGS OF THE THIRTIETH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2021, 2021, : 4312 - 4321
  • [29] Exploring generative adversarial networks and adversarial training
    Sajeeda A.
    Hossain B.M.M.
    Int. J. Cogn. Comp. Eng., (78-89): : 78 - 89
  • [30] Efficient Adversarial Training with Transferable Adversarial Examples
    Zheng, Haizhong
    Zhang, Ziqi
    Gu, Juncheng
    Lee, Honglak
    Prakash, Atul
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2020, : 1178 - 1187