Batch Normalization Increases Adversarial Vulnerability and Decreases Adversarial Transferability: A Non-Robust Feature Perspective
Philipp Benz, Chaoning Zhang, In So Kweon
Abstract
Batch normalization (BN) has been widely used in modern deep neural networks (DNNs) due to improved convergence. BN is observed to increase the model accuracy while at the cost of adversarial robustness. There is an increasing interest in the ML community to understand the impact of BN on DNNs, especially related to the model robustness. This work attempts to understand the impact of BN on DNNs from a non-robust feature perspective. Straightforwardly, the improved accuracy can be attributed to the better utilization of useful features. It remains unclear whether BN mainly favors learning robust features (RFs) or non-robust features (NRFs). Our work presents empirical evidence that supports that BN shifts a model towards being more dependent on NRFs. To facilitate the analysis of such a feature robustness shift, we propose a framework for disentangling robust usefulness into robustness and usefulness. Extensive analysis under the proposed framework yields valuable insight on the DNN behavior regarding robustness, e.g. DNNs first mainly learn RFs and then NRFs. The insight that RFs transfer better than NRFs, further inspires simple techniques to strengthen transfer-based black-box attacks. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers13
- Removing Batch Normalization Boosts Adversarial TrainingHaotao Wang, Aston Zhang, Shuai Zheng, Xingjian Shi et al.ICML 2022 · 51 citations
- Neural Mean Discrepancy for Efficient Out-of-Distribution DetectionXin Dong, Junfeng Guo, Ang Li, Wei-Te Ting et al.CVPR 2022 · 40 citations
- Normalization Layers Are All That Sharpness-Aware Minimization NeedsMaximilian Müller, Tiffany Vlaar, David Rolnick, Matthias HeinNeurIPS 2023 · 37 citations
- Investigating Top-k White-Box and Transferable Black-box AttackChaoning Zhang, Philipp Benz, Adil Karjauv, Jae-Won Cho et al.CVPR 2022 · 34 citations
- Transferable Adversarial Attacks on SAM and Its Downstream ModelsSong Xia, Wenhan Yang, Yi Yu, Xun Lin et al.NeurIPS 2024 · 29 citations
Builds on8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Improving robustness against common corruptions by covariate shift adaptationSteffen Schneider, Evgenia Rusak, Luisa Eck, Oliver Bringmann et al.NeurIPS 2020 · 688 citations
- High-Performance Large-Scale Image Recognition Without NormalizationAndy Brock, Soham De, Samuel L. Smith, Karen SimonyanICML 2021 · 613 citations
- Do Adversarially Robust ImageNet Models Transfer Better?Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor et al.NeurIPS 2020 · 506 citations
- Robust Pre-Training by Adversarial Contrastive LearningZiyu Jiang, Tianlong Chen, Ting Chen, Zhangyang WangNeurIPS 2020 · 284 citations
Related papers
- Intriguing Properties of Adversarial Training at ScaleCihang Xie, Alan L. YuilleICLR 2020 · 66 citations
- Limitations of Post-Hoc Feature Alignment for RobustnessCollin Burns, Jacob SteinhardtCVPR 2021
- CARTL: Cooperative Adversarially-Robust Transfer LearningDian Chen, Hongxin Hu, Qian Wang, Yinli Li et al.ICML 2021 · 15 citations
- Training BatchNorm and Only BatchNorm: On the Expressive Power of Random Features in CNNsJonathan Frankle, David J. Schwab, Ari S. MorcosICLR 2021 · 163 citations
- Random Normalization Aggregation for Adversarial DefenseMinjing Dong, Xinghao Chen, Yunhe Wang, Chang XuNeurIPS 2022 · 23 citations
