Adversarial Vertex Mixup: Toward Better Adversarially Robust Generalization

被引:72
|
作者
Lee, Saehyung
Lee, Hyungyu
Yoon, Sungroh [1 ]
机构
[1] Seoul Natl Univ, Elect & Comp Engn, ASRI, INMC, Seoul 08826, South Korea
基金
新加坡国家研究基金会;
关键词
D O I
10.1109/CVPR42600.2020.00035
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial examples cause neural networks to produce incorrect outputs with high confidence. Although adversarial training is one of the most effective forms of defense against adversarial examples, unfortunately, a large gap exists between test accuracy and training accuracy in adversarial training. In this paper, we identify Adversarial Feature Overfitting (AFO), which may cause poor adversarially robust generalization, and we show that adversarial training can overshoot the optimal point in terms of robust generalization, leading to AFO in our simple Gaussian model. Considering these theoretical results, we present soft labeling as a solution to the AFO problem. Furthermore, we propose Adversarial Vertex mixup (AVmixup), a soft-labeled data augmentation approach for improving adversarially robust generalization. We complement our theoretical analysis with experiments on CIFAR10, CIFAR100, SVHN, and Tiny ImageNet, and show that AVmixup significantly improves the robust generalization performance and that it reduces the trade-off between standard accuracy and adversarial robustness.
引用
收藏
页码:269 / 278
页数:10
相关论文
共 50 条
  • [21] Robust Semantic Parsing with Adversarial Learning for Domain Generalization
    Marzinotto, Gabriel
    Damnati, Geraldine
    Bechet, Frederic
    Favre, Benoit
    2019 CONFERENCE OF THE NORTH AMERICAN CHAPTER OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS: HUMAN LANGUAGE TECHNOLOGIES(NAACL HLT 2019), VOL. 2 (INDUSTRY PAPERS), 2019, : 166 - 173
  • [22] More Data Can Expand the Generalization Gap Between Adversarially Robust and Standard Models
    Chen, Lin
    Min, Yifei
    Zhang, Mingrui
    Karbasi, Amin
    25TH AMERICAS CONFERENCE ON INFORMATION SYSTEMS (AMCIS 2019), 2019,
  • [23] Adversarial and Random Transformations for Robust Domain Adaptation and Generalization
    Xiao, Liang
    Xu, Jiaolong
    Zhao, Dawei
    Shang, Erke
    Zhu, Qi
    Dai, Bin
    SENSORS, 2023, 23 (11)
  • [24] More Data Can Expand the Generalization Gap Between Adversarially Robust and Standard Models
    Chen, Lin
    Min, Yifei
    Zhang, Mingrui
    Karbasi, Amin
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 119, 2020, 119
  • [25] Towards Better Robust Generalization with Shift Consistency Regularization
    Zhang, Shufei
    Qian, Zhuang
    Huang, Kaizhu
    Wang, Qiufeng
    Zhang, Rui
    Yi, Xinping
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 139, 2021, 139
  • [26] Certifying Better Robust Generalization for Unsupervised Domain Adaptation
    Gao, Zhicliang
    Zhang, Shufei
    Huang, Kaizhu
    Wang, Qiufeng
    Zhang, Rui
    Zhong, Chaoliang
    PROCEEDINGS OF THE 30TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2022, 2022, : 2399 - 2410
  • [27] Toward Better Generalization Bounds with Locally Elastic Stability
    Deng, Zhun
    He, Hangfeng
    Su, Weijie J.
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 139, 2021, 139
  • [28] VEHIGAN: Generative Adversarial Networks for Adversarially Robust V2X Misbehavior Detection Systems
    Shahriar, Md Hasan
    Ansari, Mohammad Raashid
    Monteuuist, Jean-Philippe
    Chen, Cong
    Petitt, Jonathan
    Hou, Y. Thomas
    Lou, Wenjing
    2024 IEEE 44TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, ICDCS 2024, 2024, : 1294 - 1305
  • [29] Inter-feature Relationship Certifies Robust Generalization of Adversarial Training
    Zhang, Shufei
    Qian, Zhuang
    Huang, Kaizhu
    Wang, Qiu-Feng
    Gu, Bin
    Xiong, Huan
    Yi, Xinping
    INTERNATIONAL JOURNAL OF COMPUTER VISION, 2024, 132 (12) : 5565 - 5581
  • [30] Toward Robust Sensing for Autonomous Vehicles: An Adversarial Perspective
    Modas, Apostolos
    Sanchez-Matilla, Ricardo
    Frossard, Pascal
    Cavallaro, Andrea
    IEEE SIGNAL PROCESSING MAGAZINE, 2020, 37 (04) : 14 - 23