Implicit Bias of Gradient Descent based Adversarial Training on Separable Data
Yan Li, Ethan X. Fang, Huan Xu, Tuo Zhao
摘要
Adversarial training is a principled approach for training robust neural networks. Despite of tremendous successes in practice, its theoretical properties still remain largely unexplored. In this paper, we provide new theoretical insights of gradient descent based adversarial training by studying its computational properties, specifically on its implicit bias. We take the binary classification task on linearly separable data as an illustrative example, where the loss asymptotically attains its infimum as the parameter diverges to infinity along certain directions. Specifically, we show that for any fixed iteration , when the adversarial perturbation during training has proper bounded L2 norm, the classifier learned by gradient descent based adversarial training converges in direction to the maximum L2 norm margin classifier at the rate of , significantly faster than the rate O(1/\log T} of training with clean data. In addition, when the adversarial perturbation during training has bounded Lq norm, the resulting classifier converges in direction to a maximum mixed-norm margin classifier, which has a natural interpretation of robustness, as being the maximum L2 norm margin classifier under worst-case bounded Lq norm perturbation to the data. Our findings provide theoretical backups for adversarial training that it indeed promotes robustness against adversarial perturbation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Large Learning Rate Tames Homogeneity: Convergence and Balancing EffectYuqing Wang, Minshuo Chen, Tuo Zhao, Molei TaoICLR 2022 · 被引用 53 次
- Adversarial Robustness with Semi-Infinite Constrained LearningAlexander Robey, Luiz F. O. Chamon, George J. Pappas, Hamed Hassani 等NeurIPS 2021 · 被引用 51 次
- The Implicit Bias for Adaptive Optimization Algorithms on Homogeneous Neural NetworksBohan Wang, Qi Meng, Wei Chen, Tie-Yan LiuICML 2021 · 被引用 45 次
- Robust large-margin learning in hyperbolic spaceMelanie Weber, Manzil Zaheer, Ankit Singh Rawat, Aditya Krishna Menon 等NeurIPS 2020 · 被引用 36 次
- Boosting Generative Zero-Shot Learning by Synthesizing Diverse Features with Attribute AugmentationXiaojie Zhao, Yuming Shen, Shidong Wang, Haofeng ZhangAAAI 2022 · 被引用 34 次
它引用的顶会 Paper2
相关 Paper
- Implicit Bias of Adversarial Training for Deep Neural NetworksBochen Lv, Zhanxing ZhuICLR 2022 · 被引用 8 次
- Adversarial Training Can Provably Improve Robustness: Theoretical Analysis of Feature Learning Process Under Structured DataBinghui Li, Yuanzhi LiICLR 2025
- Feature Averaging: An Implicit Bias of Gradient Descent Leading to Non-Robustness in Neural NetworksBinghui Li, Zhixuan Pan, Kaifeng Lyu, Jian LiICLR 2025
- MMA Training: Direct Input Space Margin Maximization through Adversarial TrainingGavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, Ruitong HuangICLR 2020 · 被引用 308 次
- Adversarial Training and Provable Robustness: A Tale of Two ObjectivesJiameng Fan, Wenchao LiAAAI 2021 · 被引用 23 次
