Understanding adversarial training: Increasing local stability of supervised models through robust optimization

被引:143
|
作者
Shaham, Uri [1 ]
Yamada, Yutaro [2 ]
Negahban, Sahand [2 ]
机构
[1] Yale Univ, Ctr Outcome Res, 200 Church St, New Haven, CT 06510 USA
[2] Yale Univ, Dept Stat, 24 Hillhouse St, New Haven, CT 06511 USA
关键词
Adversarial examples; Robust optimization; Non-parametric supervised models; Deep learning; NETWORKS;
D O I
10.1016/j.neucom.2018.04.027
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
We show that adversarial training of supervised learning models is in fact a robust optimization procedure. To do this, we establish a general framework for increasing local stability of supervised learning models using robust optimization. The framework is general and broadly applicable to differentiable non-parametric models, e.g., Artificial Neural Networks (ANNs). Using an alternating minimization-maximization procedure, the loss of the model is minimized with respect to perturbed examples that are generated at each parameter update, rather than with respect to the original training data. Our proposed framework generalizes adversarial training, as well as previous approaches for increasing local stability of ANNs. Experimental results reveal that our approach increases the robustness of the network to existing adversarial examples, while making it harder to generate new ones. Furthermore, our algorithm improves the accuracy of the networks also on the original test data. (C) 2018 Elsevier B.V. All rights reserved.
引用
收藏
页码:195 / 204
页数:10
相关论文
共 50 条
  • [31] Robust Optimization Models For Local Flexibility Characterization of Virtual Power Plants
    De Filippo, Allegra
    Lombardi, Michele
    Milano, Michela
    AIXIA 2021 - ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, 13196 : 609 - 623
  • [32] TRAINING ROBUST ZERO-SHOT VOICE CONVERSION MODELS WITH SELF-SUPERVISED FEATURES
    Trung Dang
    Dung Tran
    Chin, Peter
    Koishida, Kazuhito
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 6557 - 6561
  • [33] Revisiting and Advancing Fast Adversarial Training Through the Lens of Bi-Level Optimization
    Zhang, Yihua
    Zhang, Guanhua
    Khanduri, Prashant
    Hong, Mingyi
    Chang, Shiyu
    Liu, Sijia
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [34] Understanding Stability of Noisy Networks through Centrality Measures and Local Connections
    Ufimtsev, Vladimir
    Sarkar, Soumya
    Mukherjee, Animesh
    Bhowmick, Sanjukta
    CIKM'16: PROCEEDINGS OF THE 2016 ACM CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, 2016, : 2347 - 2352
  • [35] Enhancing Photovoltaic Grid Integration through Generative Adversarial Network-Enhanced Robust Optimization
    Gu, Zhiming
    Pan, Tingzhe
    Li, Bo
    Jin, Xin
    Liao, Yaohua
    Feng, Junhao
    Su, Shi
    Liu, Xiaoxin
    ENERGIES, 2024, 17 (19)
  • [36] Addressing The False Negative Problem of Deep Learning MRI Reconstruction Models by Adversarial Attacks and Robust Training
    Cheng, Kaiyang
    Caliva, Francesco
    Shah, Rutwik
    Han, Misung
    Majumdar, Sharmila
    Pedoia, Valentina
    MEDICAL IMAGING WITH DEEP LEARNING, VOL 121, 2020, 121 : 121 - 135
  • [37] Increasing Superstructure Optimization Capacity Through Self-Learning Surrogate Models
    Granacher, Julia
    Kantor, Ivan Daniel
    Marechal, Francois
    FRONTIERS IN CHEMICAL ENGINEERING, 2021, 3
  • [38] Model Free Method of Screening Training Data for Adversarial Datapoints Through Local Lipschitz Quotient Analysis
    Kamienski, Emily
    Asada, Harry
    IEEE ROBOTICS AND AUTOMATION LETTERS, 2024, 9 (12): : 11122 - 11129
  • [39] A reconciliation of local and global models for bone remodeling through optimization theory
    Subbarayan, G
    Bartel, DL
    JOURNAL OF BIOMECHANICAL ENGINEERING-TRANSACTIONS OF THE ASME, 2000, 122 (01): : 72 - 76
  • [40] AatMatch: Adaptive Adversarial Training in Semi-Supervised Learning Based on Data-Driven Decision-Making Models
    Li, Kuan
    Lian, Qianzhi
    Gao, Can
    Zhang, Fuyong
    SYSTEMS, 2023, 11 (05):