Semantic Perturbations with Normalizing Flows for Improved Generalization
Oguz Kaan Yüksel, Sebastian U. Stich, Martin Jaggi, Tatjana Chavdarova
Abstract
Data augmentation is a widely adopted technique for avoiding overfitting when training deep neural networks. However, this approach requires domain-specisfic knowledge and is often limited to a fixed set of hard-coded transformations. Recently, several works proposed to use generative models for generating semantically meaningful perturbations to train a classifier. However, because accurate encoding and decoding are critical, these methods, which use architectures that approximate the latent-variable inference, remained limited to pilot studies on small datasets. Exploiting the exactly reversible encoder-decoder structure of normalizing flows, we perform on-manifold perturbations in the latent space to define fully unsupervised data augmentations. We demonstrate that such perturbations match the performance of advanced data augmentation techniques-reaching 96.6% test accuracy for CIFAR-10 using ResNet-18 and outperform existing methods, particularly in low data regimes-yielding 10-25% relative improvement of test accuracy from classical training. We find that our latent adversarial perturbations adaptive to the classifier throughout its training are most effective, yielding the first test accuracy improvement results on real-world datasets-CIFAR-10/100-via latent-space perturbations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- READ: Retrieval-Enhanced Asymmetric Diffusion for Motion PlanningTakeru Oba, Matthew R. Walter, Norimichi UkitaCVPR 2024 · 3 citations
- Countering Personalized Text-to-Image Generation with Influence WatermarksHanwen Liu, Zhicheng Sun, Yadong MuCVPR 2024
Builds on10
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- RandAugment: Practical Automated Data Augmentation with a Reduced Search SpaceEkin Dogus Cubuk, Barret Zoph, Jonathon Shlens, Quoc LeNeurIPS 2020 · 4,453 citations
- Training Generative Adversarial Networks with Limited DataTero Karras, Miika Aittala, Janne Hellsten, Samuli Laine et al.NeurIPS 2020 · 2,345 citations
- Perceptual Adversarial Robustness: Defense Against Unseen Threat ModelsCassidy Laidlaw, Sahil Singla, Soheil FeiziICLR 2021 · 217 citations
- Adversarial AutoAugmentXinyu Zhang, Qiang Wang, Jian Zhang, Zhao ZhongICLR 2020 · 210 citations
Related papers
- Learning to Transform for Generalizable Instance-wise InvarianceUtkarsh Singhal, Carlos Esteves, Ameesh Makadia, Stella X. YuICCV 2023 · 3 citations
- AdvFlow: Inconspicuous Black-box Adversarial Attacks using Normalizing FlowsHadi Mohaghegh Dolatabadi, Sarah M. Erfani, Christopher LeckieNeurIPS 2020 · 75 citations
- Deep Residual Flow for Out of Distribution DetectionEv Zisselman, Aviv TamarCVPR 2020
- Dual Manifold Adversarial Robustness: Defense against Lp and non-Lp Adversarial AttacksWei-An Lin, Chun Pong Lau, Alexander Levine, Rama Chellappa et al.NeurIPS 2020 · 70 citations
- Data Augmentation Can Improve RobustnessSylvestre-Alvise Rebuffi, Sven Gowal, Dan Andrei Calian, Florian Stimberg et al.NeurIPS 2021 · 427 citations
