Adversarial training with distribution normalization and margin balance

被引:9
|
作者
Cheng, Zhen [1 ,2 ]
Zhu, Fei [1 ,2 ]
Zhang, Xu-Yao [1 ,2 ]
Liu, Cheng-Lin [1 ,2 ]
机构
[1] Chinese Acad Sci, Natl Lab Pattern Recognit NLPR, Inst Automat, Beijing 100190, Peoples R China
[2] Univ Chinese Acad Sci UCAS, Sch Artificial Intelligence, Beijing 100049, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial robustness; Adversarial training; Distribution normalization; Margin balance;
D O I
10.1016/j.patcog.2022.109182
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training is the most effective method to improve adversarial robustness. However, it does not explicitly regularize the feature space during training. Adversarial attacks usually move a sample it-eratively along the direction which causes the steepest ascent of classification loss by crossing decision boundary. To alleviate this problem, we propose to regularize the distributions of different classes to increase the difficulty of finding an attacking direction. Specifically, we propose two strategies named Distribution Normalization (DN) and Margin Balance (MB) for adversarial training. The purpose of DN is to normalize the features of each class to have identical variance in every direction, in order to elimi-nate easy-to-attack intra-class directions. The purpose of MB is to balance the margins between different classes, making it harder to find confusing class directions (i.e., those with smaller margins) to attack. When integrated with adversarial training, our method can significantly improve adversarial robustness. Extensive experiments under white-box, black-box, and adaptive attacks demonstrate the effectiveness of our method over other state-of-the-art methods.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:11
相关论文
共 50 条
  • [31] Universal Adversarial Training
    Shafahi, Ali
    Najibi, Mahyar
    Xu, Zheng
    Dickerson, John
    Davis, Larry S.
    Goldstein, Tom
    THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 5636 - 5643
  • [32] Adversarial Training for Free!
    Shafahi, Ali
    Najibi, Mahyar
    Ghiasi, Amin
    Xu, Zheng
    Dickerson, John
    Studer, Christoph
    Davis, Larry S.
    Taylor, Gavin
    Goldstein, Tom
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [33] Bridged adversarial training
    Kim, Hoki
    Lee, Woojin
    Lee, Sungyoon
    Lee, Jaewook
    NEURAL NETWORKS, 2023, 167 : 266 - 282
  • [34] Subspace Adversarial Training
    Li, Tao
    Wu, Yingwen
    Chen, Sizhe
    Fang, Kun
    Huang, Xiaolin
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2022, : 13399 - 13408
  • [35] Curriculum Adversarial Training
    Cai, Qi-Zhi
    Liu, Chang
    Song, Dawn
    PROCEEDINGS OF THE TWENTY-SEVENTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2018, : 3740 - 3747
  • [36] On the Connection between Invariant Learning and Adversarial Training for Out-of-Distribution Generalization
    Xin, Shiji
    Wang, Yifei
    Su, Jingtong
    Wang, Yisen
    THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 9, 2023, : 10519 - 10527
  • [37] Max-Margin Generative Adversarial Networks
    Gao Wanshun
    Wang Zhonghao
    PROCEEDINGS OF 2018 TENTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTATIONAL INTELLIGENCE (ICACI), 2018, : 607 - 612
  • [38] Face illumination normalization based on generative adversarial network
    Dequan Guo
    Lingrui Zhu
    Shenggui Ling
    Tianxiang Li
    Gexiang Zhang
    Qiang Yang
    Ping Wang
    Shiqi Jiang
    Sidong Wu
    Junbao Liu
    Natural Computing, 2023, 22 : 105 - 117
  • [39] Boosting Adversarial Transferability by Batchwise Amplitude Spectrum Normalization
    Dang, Qianlong
    Zhan, Tao
    Gong, Maoguo
    He, Xiaoyu
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2025, 63
  • [40] Adversarial Attacks and Batch Normalization: A Batch Statistics Perspective
    Muhammad, Awais
    Shamshad, Fahad
    Bae, Sung-Ho
    IEEE ACCESS, 2023, 11 : 96449 - 96459