Stability Analysis and Generalization Bounds of Adversarial Training
Jiancong Xiao, Yanbo Fan, Ruoyu Sun, Jue Wang, Zhi-Quan Luo
摘要
In adversarial machine learning, deep neural networks can fit the adversarial examples on the training dataset but have poor generalization ability on the test set. This phenomenon is called robust overfitting, and it can be observed when adversarially training neural nets on common datasets, including SVHN, CIFAR-10, CIFAR-100, and ImageNet. In this paper, we study the robust overfitting issue of adversarial training by using tools from uniform stability. One major challenge is that the outer function (as a maximization of the inner function) is nonsmooth, so the standard technique (e.g., hardt et al., 2016) cannot be applied. Our approach is to consider -approximate smoothness: we show that the outer function satisfies this modified smoothness assumption with being a constant related to the adversarial perturbation . Based on this, we derive stability-based generalization bounds for stochastic gradient descent (SGD) on the general class of -approximate smooth functions, which covers the adversarial loss. Our results suggest that robust test accuracy decreases in when is large, with a speed between and . This phenomenon is also observed in practice. Additionally, we show that a few popular techniques for adversarial training (e.g., early stopping, cyclic learning rate, and stochastic weight averaging) are stability-promoting in theory.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Boosting the Transferability of Adversarial Attacks with Reverse Adversarial PerturbationZeyu Qin, Yanbo Fan, Yi Liu, Li Shen 等NeurIPS 2022 · 被引用 135 次
- RoPINN: Region Optimized Physics-Informed Neural NetworksHaixu Wu, Huakun Luo, Yuezhou Ma, Jianmin Wang 等NeurIPS 2024 · 被引用 50 次
- On the Stability and Generalization of Meta-LearningYunjuan Wang, Raman AroraNeurIPS 2024 · 被引用 12 次
- Transformed Low-Rank Parameterization Can Help Robust Generalization for Tensor Neural NetworksAndong Wang, Chao Li, Mingyuan Bai, Zhong Jin 等NeurIPS 2023 · 被引用 12 次
- A Closer Look at Curriculum Adversarial Training: From an Online PerspectiveLianghe Shi, Weiwei LiuAAAI 2024 · 被引用 7 次
它引用的顶会 Paper15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 被引用 1,026 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 被引用 917 次
相关 Paper
- Uniformly Stable Algorithms for Adversarial Training and BeyondJiancong Xiao, Jiawei Zhang, Zhi-Quan Luo, Asuman E. OzdaglarICML 2024 · 被引用 2 次
- Robust Overfitting may be mitigated by properly learned smootheningTianlong Chen, Zhenyu Zhang, Sijia Liu, Shiyu Chang 等ICLR 2021 · 被引用 69 次
- Consistency Regularization for Adversarial RobustnessJihoon Tack, Sihyun Yu, Jongheon Jeong, Minseon Kim 等AAAI 2022 · 被引用 75 次
- Data Augmentation Can Improve RobustnessSylvestre-Alvise Rebuffi, Sven Gowal, Dan Andrei Calian, Florian Stimberg 等NeurIPS 2021 · 被引用 427 次
- Relating Adversarially Robust Generalization to Flat MinimaDavid Stutz, Matthias Hein, Bernt SchieleICCV 2021 · 被引用 80 次
