Understanding and Improving Ensemble Adversarial Defense
Yian Deng, Tingting Mu
Abstract
The strategy of ensemble has become popular in adversarial defense, which trains multiple base classifiers to defend against adversarial attacks in a cooperative manner. Despite the empirical success, theoretical explanations on why an ensemble of adversarially trained classifiers is more robust than single ones remain unclear. To fill in this gap, we develop a new error theory dedicated to understanding ensemble adversarial defense, demonstrating a provable 0-1 loss reduction on challenging sample sets in an adversarial defense scenario. Guided by this theory, we propose an effective approach to improve ensemble adversarial defense, named interactive global adversarial training (iGAT). The proposal includes (1) a probabilistic distributing rule that selectively allocates to different base classifiers adversarial examples that are globally challenging to the ensemble, and (2) a regularization term to rescue the severest weaknesses of the base classifiers. Being tested over various existing ensemble adversarial defense techniques, iGAT is capable of boosting their performance by increases up to 17% evaluated using CIFAR10 and CIFAR100 datasets under both white-box and black-box attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1219af47-1397-4e71-a0aa-5436829cc8b8Cited by top-tier papers7
- Understanding and Improving Adversarial Collaborative Filtering for Robust RecommendationKaike Zhang, Qi Cao, Yunfan Wu, Fei Sun et al.NeurIPS 2024 · 11 citations
- AUTE: Peer-Alignment and Self-Unlearning Boost Adversarial Robustness for Training Ensemble ModelsLifeng Huang, Tian Su, Chengying Gao, Ning Liu et al.AAAI 2025 · 2 citations
- Boosting the Robustness-Accuracy Trade-off of SNNs by Robust Temporal Self-EnsembleJihang Wang, Dongcheng Zhao, Ruolin Chen, Qian Zhang et al.AAAI 2026 · 1 citation
- Understanding Model Ensemble in Transferable Adversarial AttackWei Yao, Zeliang Zhang, Huayi Tang, Yong LiuICML 2025
- On the Diversity of Adversarial Ensemble LearningJun-Qi Guo, Meng-Zhang Qian, Wei Gao, Zhi-Hua ZhouICML 2025
Builds on11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 917 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
- Understanding and Mitigating the Tradeoff between Robustness and AccuracyAditi Raghunathan, Sang Michael Xie, Fanny Yang, John C. Duchi et al.ICML 2020 · 252 citations
Related papers
- Exploiting Joint Robustness to Adversarial PerturbationsAli Dabouei, Sobhan Soleymani, Fariborz Taherkhani, Jeremy M. Dawson et al.CVPR 2020
- On the Certified Robustness for Ensemble Models and BeyondZhuolin Yang, Linyi Li, Xiaojun Xu, Bhavya Kailkhura et al.ICLR 2022 · 57 citations
- Adversarial Defence by Diversified Simultaneous Training of Deep EnsemblesBo Huang, Zhiwei Ke, Yi Wang, Wei Wang et al.AAAI 2021 · 20 citations
- Self-ensemble Adversarial Training for Improved RobustnessHongjun Wang, Yisen WangICLR 2022 · 61 citations
- Improving Adversarial Robustness via Guided Complement EntropyHao-Yun Chen, Jhao-Hong Liang, Shih-Chieh Chang, Jia-Yu Pan et al.ICCV 2019 · 51 citations
