Once-for-All Adversarial Training: In-Situ Tradeoff between Robustness and Accuracy for Free
Haotao Wang, Tianlong Chen, Shupeng Gui, Ting-Kuei Hu, Ji Liu, Zhangyang Wang
摘要
Adversarial training and its many variants substantially improve deep network robustness, yet at the cost of compromising standard accuracy. Moreover, the training process is heavy and hence it becomes impractical to thoroughly explore the trade-off between accuracy and robustness. This paper asks this new question: how to quickly calibrate a trained model in-situ, to examine the achievable trade-offs between its standard and robust accuracies, without (re-)training it many times? Our proposed framework, Once-for-all Adversarial Training (OAT), is built on an innovative model-conditional training framework, with a controlling hyper-parameter as the input. The trained model could be adjusted among different standard and robust accuracies "for free" at testing time. As an important knob, we exploit dual batch normalization to separate standard and adversarial feature statistics, so that they can be learned in one model without degrading performance. We further extend OAT to a Once-for-all Adversarial Training and Slimming (OATS) framework, that allows for the joint trade-off among accuracy, robustness and runtime efficiency. Experiments show that, without any re-training nor ensembling, OAT/OATS achieve similar or even superior performance compared to dedicatedly trained models at various configurations. Our codes and pretrained models are available at: https://github.com/VITA-Group/Once-for-All-Adversarial-Training . Motivation and background Deep neural networks (DNNs) are nowadays well-known to be vulnerable to adversarial examples [1, 2] . With the growing usage of DNNs on security sensitive applications, such as self-driving [3] and bio-metrics [4], a critical concern has been raised to carefully examine the worst-case accuracy of deployed DNNs on crafted attacks (denoted as robust accuracy, or robustness for short, following [5] ), in addition to their average accuracy on standard inputs (denoted as standard accuracy, or accuracy for short). Among a variety of adversarial defense methods proposed to enhance DNN robustness, adversarial training (AT) based methods [5, 6, 7] are consistently top-performers. While adversarial defense methods are gaining increasing attention and popularity in safety/securitycritical applications, their downsides are also noteworthy. Firstly, most adversarial defense methods, including adversarial training, come at the price of compromising the standard accuracy [8] . That * The first two authors contributed equally. 34th Conference on Neural Information Processing Systems (NeurIPS 2020),
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- Geometry-aware Instance-reweighted Adversarial TrainingJingfeng Zhang, Jianing Zhu, Gang Niu, Bo Han 等ICLR 2021 · 被引用 316 次
- Robustness and Accuracy Could Be Reconcilable by (Proper) DefinitionTianyu Pang, Min Lin, Xiao Yang, Jun Zhu 等ICML 2022 · 被引用 168 次
- AugMax: Adversarial Composition of Random Augmentations for Robust TrainingHaotao Wang, Chaowei Xiao, Jean Kossaifi, Zhiding Yu 等NeurIPS 2021 · 被引用 153 次
- Reliable Adversarial Distillation with Unreliable TeachersJianing Zhu, Jiangchao Yao, Bo Han, Jingfeng Zhang 等ICLR 2022 · 被引用 92 次
- Probabilistic Margins for Instance Reweighting in Adversarial TrainingQizhou Wang, Feng Liu, Bo Han, Tongliang Liu 等NeurIPS 2021 · 被引用 84 次
它引用的顶会 Paper9
- MMA Training: Direct Input Space Margin Maximization through Adversarial TrainingGavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, Ruitong HuangICLR 2020 · 被引用 308 次
- Adversarial Robustness vs. Model Compression, or Both?Shaokai Ye, Xue Lin, Kaidi Xu, Sijia Liu 等ICCV 2019 · 被引用 180 次
- Controllable Artistic Text Style Transfer via Shape-Matching GANShuai Yang, Zhangyang Wang, Zhaowen Wang, Ning Xu 等ICCV 2019 · 被引用 110 次
- Triple Wins: Boosting Accuracy, Robustness and Efficiency Together by Enabling Input-Adaptive InferenceTing-Kuei Hu, Tianlong Chen, Haotao Wang, Zhangyang WangICLR 2020 · 被引用 89 次
- Jacobian Adversarially Regularized Networks for RobustnessAlvin Chan, Yi Tay, Yew-Soon Ong, Jie FuICLR 2020 · 被引用 81 次
相关 Paper
- Improving Generalization of Adversarial Training via Robust Critical Fine-TuningKaijie Zhu, Xixu Hu, Jindong Wang, Xing Xie 等ICCV 2023 · 被引用 38 次
- Revisiting adapters with adversarial trainingSylvestre-Alvise Rebuffi, Francesco Croce, Sven GowalICLR 2023
- Advancing Example Exploitation Can Alleviate Critical Challenges in Adversarial TrainingYao Ge, Yun Li, Keji Han, Junyi Zhu 等ICCV 2023 · 被引用 6 次
- Removing Batch Normalization Boosts Adversarial TrainingHaotao Wang, Aston Zhang, Shuai Zheng, Xingjian Shi 等ICML 2022 · 被引用 51 次
- Failure Cases Are Better Learned but Boundary Says Sorry: Facilitating Smooth Perception Change for Accuracy-Robustness Trade-Off in Adversarial TrainingYanyun Wang, Li LiuICCV 2025 · 被引用 1 次
