Efficient and Effective Augmentation Strategy for Adversarial Training
Sravanti Addepalli, Samyak Jain, Venkatesh Babu R.
Abstract
Adversarial training of Deep Neural Networks is known to be significantly more data-hungry when compared to standard training. Furthermore, complex data augmentations such as AutoAugment, which have led to substantial gains in standard training of image classifiers, have not been successful with Adversarial Training. We first explain this contrasting behavior by viewing augmentation during training as a problem of domain generalization, and further propose Diverse Augmentation-based Joint Adversarial Training (DAJAT) to use data augmentations effectively in adversarial training. We aim to handle the conflicting goals of enhancing the diversity of the training dataset and training with data that is close to the test distribution by using a combination of simple and complex augmentations with separate batch normalization layers during training. We further utilize the popular Jensen-Shannon divergence loss to encourage the joint learning of the diverse augmentations, thereby allowing simple augmentations to guide the learning of complex ones. Lastly, to improve the computational efficiency of the proposed method, we propose and utilize a two-step defense, Ascending Constraint Adversarial Training (ACAT), that uses an increasing epsilon schedule and weight-space smoothing to prevent gradient masking. The proposed method DAJAT achieves substantially better robustness-accuracy trade-off when compared to existing methods on the RobustBench Leaderboard on ResNet-18 and WideResNet-34-10. The code for implementing DAJAT is available here: https://github.com/val-iisc/DAJAT.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 95832ae7-06fe-4912-8716-4aef39f44c1aCited by top-tier papers19
- Decoupled Kullback-Leibler Divergence LossJiequan Cui, Zhuotao Tian, Zhisheng Zhong, Xiaojuan Qi et al.NeurIPS 2024 · 119 citations
- Investigating Generalizability of Speech-based Suicidal Ideation Detection Using Mobile PhonesArvind Pillai, Subigya Kumar Nepal, Weichen Wang, Matthew Nemesure et al.UbiComp 2024 · 26 citations
- Efficient Adversarial Contrastive Learning via Robustness-Aware Coreset SelectionXilie Xu, Jingfeng Zhang, Feng Liu, Masashi Sugiyama et al.NeurIPS 2023 · 26 citations
- DAT: Improving Adversarial Robustness via Generative Amplitude Mix-up in Frequency DomainFengpeng Li, Kemou Li, Haiwei Wu, Jinyu Tian et al.NeurIPS 2024 · 19 citations
- Revisiting Adversarial Training Under Long-Tailed DistributionsXinli Yue, Ningping Mou, Qian Wang, Lingchen ZhaoCVPR 2024 · 14 citations
Builds on22
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 917 citations
Related papers
- Consistency Regularization for Adversarial RobustnessJihoon Tack, Sihyun Yu, Jongheon Jeong, Minseon Kim et al.AAAI 2022 · 75 citations
- Adversarial Training of Deep Neural Networks Guided by Texture and Structural InformationZhaoxin Wang, Handing Wang, Cong Tian, Yaochu JinACM MM 2023 · 4 citations
- Self-Supervised Adversarial Training via Diverse Augmented Queries and Self-Supervised Double PerturbationRuize Zhang, Sheng Tang, Juan CaoNeurIPS 2024 · 5 citations
- IPMix: Label-Preserving Data Augmentation Method for Training Robust ClassifiersZhenglin Huang, Xiaoan Bao, Na Zhang, Qingqi Zhang et al.NeurIPS 2023 · 26 citations
- Robustness and Generalization via Generative Adversarial TrainingOmid Poursaeed, Tianxing Jiang, Harry Yang, Serge J. Belongie et al.ICCV 2021 · 35 citations
