Adversarial Training Should Be Cast as a Non-Zero-Sum Game
Alexander Robey, Fabian Latorre, George J. Pappas, Hamed Hassani, Volkan Cevher
摘要
One prominent approach toward resolving the adversarial vulnerability of deep neural networks is the two-player zero-sum paradigm of adversarial training, in which predictors are trained against adversarially chosen perturbations of data. Despite the promise of this approach, algorithms based on this paradigm have not engendered sufficient levels of robustness and suffer from pathological behavior like robust overfitting. To understand this shortcoming, we first show that the commonly used surrogate-based relaxation used in adversarial training algorithms voids all guarantees on the robustness of trained classifiers. The identification of this pitfall informs a novel non-zero-sum bilevel formulation of adversarial training, wherein each player optimizes a different objective function. Our formulation yields a simple algorithmic framework that matches and in some cases outperforms state-of-the-art attacks, attains comparable levels of robustness to standard adversarial training algorithms, and does not suffer from robust overfitting.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- High-dimensional (Group) Adversarial Training in Linear RegressionYiling Xie, Xiaoming HuoNeurIPS 2024 · 被引用 8 次
- Improving SAM Requires Rethinking its Optimization FormulationWanyun Xie, Fabian Latorre, Kimon Antonakopoulos, Thomas Pethick 等ICML 2024 · 被引用 4 次
- Towards Runtime Analysis of Population-Based Co-evolutionary Algorithms on Sparse Binary Zero-Sum GamePer Kristian Lehre, Shishen LinAAAI 2025 · 被引用 3 次
- Unlocking Global Optimality in Bilevel Optimization: A Pilot StudyQuan Xiao, Tianyi ChenICLR 2025
- Adversarial Training for Defense Against Label Poisoning AttacksMelis Ilayda Bal, Volkan Cevher, Michael MuehlebachICLR 2025
它引用的顶会 Paper26
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- WILDS: A Benchmark of in-the-Wild Distribution ShiftsPang Wei Koh, Shiori Sagawa, Henrik Marklund, Sang Michael Xie 等ICML 2021 · 被引用 1,773 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 被引用 917 次
相关 Paper
- Adversarial Policy Learning in Two-player Competitive GamesWenbo Guo, Xian Wu, Sui Huang, Xinyu XingICML 2021 · 被引用 50 次
- Robustness Guarantees for Adversarially Trained Neural NetworksPoorya Mianjy, Raman AroraNeurIPS 2023 · 被引用 4 次
- Improving Adversarial Robustness by Putting More Regularizations on Less Robust SamplesDongyoon Yang, Insung Kong, Yongdai KimICML 2023 · 被引用 15 次
- Cooperation or Competition: Avoiding Player Domination for Multi-Target Robustness via Adaptive BudgetsYimu Wang, Dinghuai Zhang, Yihan Wu, Heng Huang 等CVPR 2023
- Adversarial Training Can Provably Improve Robustness: Theoretical Analysis of Feature Learning Process Under Structured DataBinghui Li, Yuanzhi LiICLR 2025
