Lune

NeurIPS2022顶会

Stability Analysis and Generalization Bounds of Adversarial Training

Jiancong Xiao, Yanbo Fan, Ruoyu Sun, Jue Wang, Zhi-Quan Luo

2022年份
49被引次数
14顶会引用

摘要

In adversarial machine learning, deep neural networks can fit the adversarial examples on the training dataset but have poor generalization ability on the test set. This phenomenon is called robust overfitting, and it can be observed when adversarially training neural nets on common datasets, including SVHN, CIFAR-10, CIFAR-100, and ImageNet. In this paper, we study the robust overfitting issue of adversarial training by using tools from uniform stability. One major challenge is that the outer function (as a maximization of the inner function) is nonsmooth, so the standard technique (e.g., hardt et al., 2016) cannot be applied. Our approach is to consider η\eta-approximate smoothness: we show that the outer function satisfies this modified smoothness assumption with η\eta being a constant related to the adversarial perturbation ϵ\epsilon. Based on this, we derive stability-based generalization bounds for stochastic gradient descent (SGD) on the general class of η\eta-approximate smooth functions, which covers the adversarial loss. Our results suggest that robust test accuracy decreases in ϵ\epsilon when TT is large, with a speed between Ω(ϵT)\Omega(\epsilon\sqrt{T}) and O(ϵT)\mathcal{O}(\epsilon T). This phenomenon is also observed in practice. Additionally, we show that a few popular techniques for adversarial training (e.g., early stopping, cyclic learning rate, and stochastic weight averaging) are stability-promoting in theory.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper14

问问它们各自怎么用它

它引用的顶会 Paper15

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖