Towards Understanding the Dynamics of the First-Order Adversaries
Zhun Deng, Hangfeng He, Jiaoyang Huang, Weijie J. Su
Abstract
An acknowledged weakness of neural networks is their vulnerability to adversarial perturbations to the inputs. To improve the robustness of these models, one of the most popular defense mechanisms is to alternatively maximize the loss over the constrained perturbations (or called adversaries) on the inputs using projected gradient ascent and minimize over weights. In this paper, we analyze the dynamics of the maximization step towards understanding the experimentally observed effectiveness of this defense mechanism. Specifically, we investigate the non-concave landscape of the adversaries for a two-layer neural network with a quadratic loss. Our main result proves that projected gradient ascent finds a local maximum of this non-concave problem in a polynomial number of iterations with high probability. To our knowledge, this is the first work that provides a convergence analysis of the first-order adversaries. Moreover, our analysis demonstrates that, in the initial phase of adversarial training, the scale of the inputs matters in the sense that a smaller input scale leads to faster convergence of adversarial training and a "more regular" landscape. Finally, we show that these theoretical findings are in excellent agreement with a series of experiments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 23654202-88f1-416a-9a28-09ffae2040ffCited by top-tier papers5
- When and How Mixup Improves CalibrationLinjun Zhang, Zhun Deng, Kenji Kawaguchi, James ZouICML 2022 · 79 citations
- On the Algorithmic Stability of Adversarial TrainingYue Xing, Qifan Song, Guang ChengNeurIPS 2021 · 74 citations
- Adversarial Training Helps Transfer Learning via Better RepresentationsZhun Deng, Linjun Zhang, Kailas Vodrahalli, Kenji Kawaguchi et al.NeurIPS 2021 · 60 citations
- FIFA: Making Fairness More Generalizable in Classifiers Trained on Imbalanced DataZhun Deng, Jiayao Zhang, Linjun Zhang, Ting Ye et al.ICLR 2023 · 7 citations
- Algorithmic Stability Based Generalization Bounds for Adversarial TrainingRunzhi Tian, Yongyi MaoICLR 2025
Builds on1
Related papers
- Over-parameterized Adversarial Training: An Analysis Overcoming the Curse of DimensionalityYi Zhang, Orestis Plevrakis, Simon S. Du, Xingguo Li et al.NeurIPS 2020 · 56 citations
- Robustness Guarantees for Adversarially Trained Neural NetworksPoorya Mianjy, Raman AroraNeurIPS 2023 · 4 citations
- Implicit Bias of Gradient Descent based Adversarial Training on Separable DataYan Li, Ethan X. Fang, Huan Xu, Tuo ZhaoICLR 2020 · 40 citations
- A Single-Loop Smoothed Gradient Descent-Ascent Algorithm for Nonconvex-Concave Min-Max ProblemsJiawei Zhang, Peijun Xiao, Ruoyu Sun, Zhi-Quan LuoNeurIPS 2020 · 130 citations
- Adversarial Training is a Form of Data-dependent Operator Norm RegularizationKevin Roth, Yannic Kilcher, Thomas HofmannNeurIPS 2020 · 61 citations
