Understanding and Improving Fast Adversarial Training against Bounded Perturbations
Xuyang Zhong, Yixiao Huang, Chen Liu
摘要
This work studies fast adversarial training against sparse adversarial perturbations bounded by l 0 norm. We first demonstrate the unique challenges of employing 1 -step attacks on l 0 bounded perturbations, especially catastrophic overfitting (CO) that cannnot be properly addressed by existing fast adversarial training method for other l p norms ( p ≥ 1 ). We highlight that CO in l 0 adversarial training arises from sub-optimal perturbation locations of 1 -step attack. Some strategies like multi-(cid:15) can mitigate this sub-optimality to some extent, they lead to unstable training in turn. Theoretical and numerical analyses also reveal that the loss landscape of l 0 adversarial training is more craggy than its l ∞ , l 2 and l 1 counterparts, which exaggerates CO. To address this issue, we adopt soft labels and the trade-off loss function to smooth the adversarial loss landscape. Extensive experiments demonstrate our method can overcome the challenge of CO, achieve state-of-the-art performance, and narrow the performance gap between 1 -step and multi-step adversarial training against sparse attacks. Codes are available at https://github.com/CityU-MLO/sPGD.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper27
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu 等ICCV 2021 · 被引用 31,683 次
- A ConvNet for the 2020sZhuang Liu, Hanzi Mao, Chao-Yuan Wu, Christoph Feichtenhofer 等CVPR 2022 · 被引用 6,782 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
相关 Paper
- Towards Efficient Training and Evaluation of Robust Models against l0 Bounded Adversarial PerturbationsXuyang Zhong, Yixiao Huang, Chen LiuICML 2024 · 被引用 3 次
- Understanding Catastrophic Overfitting in Single-step Adversarial TrainingHoki Kim, Woojin Lee, Jaewook LeeAAAI 2021 · 被引用 135 次
- Towards Stable and Efficient Adversarial Training against l1 Bounded Adversarial AttacksYulun Jiang, Chen Liu, Zhichao Huang, Mathieu Salzmann 等ICML 2023 · 被引用 13 次
- Subspace Adversarial TrainingTao Li, Yingwen Wu, Sizhe Chen, Kun Fang 等CVPR 2022 · 被引用 59 次
- Make Some Noise: Reliable and Efficient Single-Step Adversarial TrainingPau de Jorge Aranda, Adel Bibi, Riccardo Volpi, Amartya Sanyal 等NeurIPS 2022 · 被引用 69 次
