Batch Normalization Increases Adversarial Vulnerability and Decreases Adversarial Transferability: A Non-Robust Feature Perspective
Philipp Benz, Chaoning Zhang, In So Kweon
摘要
Batch normalization (BN) has been widely used in modern deep neural networks (DNNs) due to improved convergence. BN is observed to increase the model accuracy while at the cost of adversarial robustness. There is an increasing interest in the ML community to understand the impact of BN on DNNs, especially related to the model robustness. This work attempts to understand the impact of BN on DNNs from a non-robust feature perspective. Straightforwardly, the improved accuracy can be attributed to the better utilization of useful features. It remains unclear whether BN mainly favors learning robust features (RFs) or non-robust features (NRFs). Our work presents empirical evidence that supports that BN shifts a model towards being more dependent on NRFs. To facilitate the analysis of such a feature robustness shift, we propose a framework for disentangling robust usefulness into robustness and usefulness. Extensive analysis under the proposed framework yields valuable insight on the DNN behavior regarding robustness, e.g. DNNs first mainly learn RFs and then NRFs. The insight that RFs transfer better than NRFs, further inspires simple techniques to strengthen transfer-based black-box attacks. 1
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Removing Batch Normalization Boosts Adversarial TrainingHaotao Wang, Aston Zhang, Shuai Zheng, Xingjian Shi 等ICML 2022 · 被引用 51 次
- Neural Mean Discrepancy for Efficient Out-of-Distribution DetectionXin Dong, Junfeng Guo, Ang Li, Wei-Te Ting 等CVPR 2022 · 被引用 40 次
- Normalization Layers Are All That Sharpness-Aware Minimization NeedsMaximilian Müller, Tiffany Vlaar, David Rolnick, Matthias HeinNeurIPS 2023 · 被引用 37 次
- Investigating Top-k White-Box and Transferable Black-box AttackChaoning Zhang, Philipp Benz, Adil Karjauv, Jae-Won Cho 等CVPR 2022 · 被引用 34 次
- Transferable Adversarial Attacks on SAM and Its Downstream ModelsSong Xia, Wenhan Yang, Yi Yu, Xun Lin 等NeurIPS 2024 · 被引用 29 次
它引用的顶会 Paper8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Improving robustness against common corruptions by covariate shift adaptationSteffen Schneider, Evgenia Rusak, Luisa Eck, Oliver Bringmann 等NeurIPS 2020 · 被引用 688 次
- High-Performance Large-Scale Image Recognition Without NormalizationAndy Brock, Soham De, Samuel L. Smith, Karen SimonyanICML 2021 · 被引用 613 次
- Do Adversarially Robust ImageNet Models Transfer Better?Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor 等NeurIPS 2020 · 被引用 506 次
- Robust Pre-Training by Adversarial Contrastive LearningZiyu Jiang, Tianlong Chen, Ting Chen, Zhangyang WangNeurIPS 2020 · 被引用 284 次
相关 Paper
- Intriguing Properties of Adversarial Training at ScaleCihang Xie, Alan L. YuilleICLR 2020 · 被引用 66 次
- Limitations of Post-Hoc Feature Alignment for RobustnessCollin Burns, Jacob SteinhardtCVPR 2021
- CARTL: Cooperative Adversarially-Robust Transfer LearningDian Chen, Hongxin Hu, Qian Wang, Yinli Li 等ICML 2021 · 被引用 15 次
- Training BatchNorm and Only BatchNorm: On the Expressive Power of Random Features in CNNsJonathan Frankle, David J. Schwab, Ari S. MorcosICLR 2021 · 被引用 163 次
- Random Normalization Aggregation for Adversarial DefenseMinjing Dong, Xinghao Chen, Yunhe Wang, Chang XuNeurIPS 2022 · 被引用 23 次
