Once-for-All Adversarial Training: In-Situ Tradeoff between Robustness and Accuracy for Free
Haotao Wang, Tianlong Chen, Shupeng Gui, Ting-Kuei Hu, Ji Liu, Zhangyang Wang
Abstract
Adversarial training and its many variants substantially improve deep network robustness, yet at the cost of compromising standard accuracy. Moreover, the training process is heavy and hence it becomes impractical to thoroughly explore the trade-off between accuracy and robustness. This paper asks this new question: how to quickly calibrate a trained model in-situ, to examine the achievable trade-offs between its standard and robust accuracies, without (re-)training it many times? Our proposed framework, Once-for-all Adversarial Training (OAT), is built on an innovative model-conditional training framework, with a controlling hyper-parameter as the input. The trained model could be adjusted among different standard and robust accuracies "for free" at testing time. As an important knob, we exploit dual batch normalization to separate standard and adversarial feature statistics, so that they can be learned in one model without degrading performance. We further extend OAT to a Once-for-all Adversarial Training and Slimming (OATS) framework, that allows for the joint trade-off among accuracy, robustness and runtime efficiency. Experiments show that, without any re-training nor ensembling, OAT/OATS achieve similar or even superior performance compared to dedicatedly trained models at various configurations. Our codes and pretrained models are available at: https://github.com/VITA-Group/Once-for-All-Adversarial-Training . Motivation and background Deep neural networks (DNNs) are nowadays well-known to be vulnerable to adversarial examples [1, 2] . With the growing usage of DNNs on security sensitive applications, such as self-driving [3] and bio-metrics [4], a critical concern has been raised to carefully examine the worst-case accuracy of deployed DNNs on crafted attacks (denoted as robust accuracy, or robustness for short, following [5] ), in addition to their average accuracy on standard inputs (denoted as standard accuracy, or accuracy for short). Among a variety of adversarial defense methods proposed to enhance DNN robustness, adversarial training (AT) based methods [5, 6, 7] are consistently top-performers. While adversarial defense methods are gaining increasing attention and popularity in safety/securitycritical applications, their downsides are also noteworthy. Firstly, most adversarial defense methods, including adversarial training, come at the price of compromising the standard accuracy [8] . That * The first two authors contributed equally. 34th Conference on Neural Information Processing Systems (NeurIPS 2020),
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 74a80b59-52da-4916-b52c-9968ab3feb03Cited by top-tier papers24
- Geometry-aware Instance-reweighted Adversarial TrainingJingfeng Zhang, Jianing Zhu, Gang Niu, Bo Han et al.ICLR 2021 · 316 citations
- Robustness and Accuracy Could Be Reconcilable by (Proper) DefinitionTianyu Pang, Min Lin, Xiao Yang, Jun Zhu et al.ICML 2022 · 168 citations
- AugMax: Adversarial Composition of Random Augmentations for Robust TrainingHaotao Wang, Chaowei Xiao, Jean Kossaifi, Zhiding Yu et al.NeurIPS 2021 · 153 citations
- Reliable Adversarial Distillation with Unreliable TeachersJianing Zhu, Jiangchao Yao, Bo Han, Jingfeng Zhang et al.ICLR 2022 · 92 citations
- Probabilistic Margins for Instance Reweighting in Adversarial TrainingQizhou Wang, Feng Liu, Bo Han, Tongliang Liu et al.NeurIPS 2021 · 84 citations
Builds on9
- MMA Training: Direct Input Space Margin Maximization through Adversarial TrainingGavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, Ruitong HuangICLR 2020 · 308 citations
- Adversarial Robustness vs. Model Compression, or Both?Shaokai Ye, Xue Lin, Kaidi Xu, Sijia Liu et al.ICCV 2019 · 180 citations
- Controllable Artistic Text Style Transfer via Shape-Matching GANShuai Yang, Zhangyang Wang, Zhaowen Wang, Ning Xu et al.ICCV 2019 · 110 citations
- Triple Wins: Boosting Accuracy, Robustness and Efficiency Together by Enabling Input-Adaptive InferenceTing-Kuei Hu, Tianlong Chen, Haotao Wang, Zhangyang WangICLR 2020 · 89 citations
- Jacobian Adversarially Regularized Networks for RobustnessAlvin Chan, Yi Tay, Yew-Soon Ong, Jie FuICLR 2020 · 81 citations
Related papers
- Improving Generalization of Adversarial Training via Robust Critical Fine-TuningKaijie Zhu, Xixu Hu, Jindong Wang, Xing Xie et al.ICCV 2023 · 38 citations
- Revisiting adapters with adversarial trainingSylvestre-Alvise Rebuffi, Francesco Croce, Sven GowalICLR 2023
- Advancing Example Exploitation Can Alleviate Critical Challenges in Adversarial TrainingYao Ge, Yun Li, Keji Han, Junyi Zhu et al.ICCV 2023 · 6 citations
- Removing Batch Normalization Boosts Adversarial TrainingHaotao Wang, Aston Zhang, Shuai Zheng, Xingjian Shi et al.ICML 2022 · 51 citations
- Failure Cases Are Better Learned but Boundary Says Sorry: Facilitating Smooth Perception Change for Accuracy-Robustness Trade-Off in Adversarial TrainingYanyun Wang, Li LiuICCV 2025 · 1 citation
