Adversarial Vertex Mixup: Toward Better Adversarially Robust Generalization

被引:72
|
作者
Lee, Saehyung
Lee, Hyungyu
Yoon, Sungroh [1 ]
机构
[1] Seoul Natl Univ, Elect & Comp Engn, ASRI, INMC, Seoul 08826, South Korea
基金
新加坡国家研究基金会;
关键词
D O I
10.1109/CVPR42600.2020.00035
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial examples cause neural networks to produce incorrect outputs with high confidence. Although adversarial training is one of the most effective forms of defense against adversarial examples, unfortunately, a large gap exists between test accuracy and training accuracy in adversarial training. In this paper, we identify Adversarial Feature Overfitting (AFO), which may cause poor adversarially robust generalization, and we show that adversarial training can overshoot the optimal point in terms of robust generalization, leading to AFO in our simple Gaussian model. Considering these theoretical results, we present soft labeling as a solution to the AFO problem. Furthermore, we propose Adversarial Vertex mixup (AVmixup), a soft-labeled data augmentation approach for improving adversarially robust generalization. We complement our theoretical analysis with experiments on CIFAR10, CIFAR100, SVHN, and Tiny ImageNet, and show that AVmixup significantly improves the robust generalization performance and that it reduces the trade-off between standard accuracy and adversarial robustness.
引用
收藏
页码:269 / 278
页数:10
相关论文
共 50 条
  • [41] Toward Robust Neural Image Compression: Adversarial Attack and Model Finetuning
    Chen, Tong
    Ma, Zhan
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2023, 33 (12) : 7842 - 7856
  • [42] Toward Robust Discriminative Projections Learning Against Adversarial Patch Attacks
    Wang, Zheng
    Nie, Feiping
    Wang, Hua
    Huang, Heng
    Wang, Fei
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (12) : 18784 - 18798
  • [43] Toward High Capacity and Robust JPEG Steganography Based on Adversarial Training
    Yang J.
    Shang F.
    Liao Y.
    Chen Y.
    Security and Communication Networks, 2023, 2023
  • [44] Revisiting Adversarial Robustness Distillation: Robust Soft Labels Make Student Better
    Zi, Bojia
    Zhao, Shihao
    Ma, Xingjun
    Jiang, Yu-Gang
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 16423 - 16432
  • [45] Towards Better Understanding of Training Certifiably Robust Models against Adversarial Examples
    Lee, Sungyoon
    Lee, Woojin
    Park, Jinseong
    Lee, Jaewook
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021,
  • [46] A Robust Adversarial Network-Based End-to-End Communications System with Strong Generalization Ability Against Adversarial Attacks
    Dong, Yudi
    Wang, Huaxia
    Yao, Yu-Dong
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 4086 - 4091
  • [47] Deep Adversarial Capsule Network for Compound Fault Diagnosis of Machinery Toward Multidomain Generalization Task
    Huang, Ruyi
    Li, Jipu
    Liao, Yixiao
    Chen, Junbin
    Wang, Zhen
    Li, Weihua
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2021, 70
  • [48] Toward Robust Networks against Adversarial Attacks for Radio Signal Modulation Classification
    Manoj, B. R.
    Santos, Pablo Millan
    Sadeghi, Meysam
    Larsson, Erik G.
    2022 IEEE 23RD INTERNATIONAL WORKSHOP ON SIGNAL PROCESSING ADVANCES IN WIRELESS COMMUNICATION (SPAWC), 2022,
  • [49] Label-Aware Neural Tangent Kernel: Toward Better Generalization and Local Elasticity
    Chen, Shuxiao
    He, Hangfeng
    Su, Weijie J.
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [50] Generalized but not Robust? Comparing the Effects of Data Modification Methods on Out-of-Domain Generalization and Adversarial Robustness
    Gokhale, Tejas
    Mishra, Swaroop
    Luo, Man
    Sachdeva, Bhavdeep Singh
    Baral, Chitta
    FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (ACL 2022), 2022, : 2705 - 2718