Towards Understanding the Regularization of Adversarial Robustness on Neural Networks
Yuxin Wen, Shuai Li, Kui Jia
摘要
The problem of adversarial examples has shown that modern Neural Network (NN) models could be rather fragile. Among the more established techniques to solve the problem, one is to require the model to be -adversarially robust (AR); that is, to require the model not to change predicted labels when any given input examples are perturbed within a certain range. However, it is observed that such methods would lead to standard performance degradation, i.e., the degradation on natural examples. In this work, we study the degradation through the regularization perspective. We identify quantities from generalization analysis of NNs; with the identified quantities we empirically find that AR is achieved by regularizing/biasing NNs towards less confident solutions by making the changes in the feature space (induced by changes in the instance space) of most layers smoother uniformly in all directions; so to a certain extent, it prevents sudden change in prediction w.r.t. perturbations. However, the end result of such smoothing concentrates samples around decision boundaries, resulting in less confident solutions, and leads to worse standard performance. Our studies suggest that one might consider ways that build AR into NNs in a gentler way to avoid the problematic regularization.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Enhance the Visual Representation via Discrete Adversarial TrainingXiaofeng Mao, Yuefeng Chen, Ranjie Duan, Yao Zhu 等NeurIPS 2022 · 被引用 48 次
- Towards Robust Recommendation via Decision Boundary-aware Graph Contrastive LearningJiakai Tang, Sunhao Dai, Zexu Sun, Xu Chen 等KDD 2024 · 被引用 15 次
- Towards Better Robustness against Common Corruptions for Unsupervised Domain AdaptationZhiqiang Gao, Kaizhu Huang, Rui Zhang, Dawei Liu 等ICCV 2023 · 被引用 8 次
- Training for Stable Explanation for FreeChao Chen, Chenghua Guo, Rufeng Chen, Guixiang Ma 等NeurIPS 2024 · 被引用 7 次
- On the Interaction of Compressibility and Adversarial RobustnessMelih Barsbey, Antônio H. Ribeiro, Umut Simsekli, Tolga BirdalICLR 2026 · 被引用 3 次
它引用的顶会 Paper1
相关 Paper
- MaxUp: Lightweight Adversarial Training With Data Augmentation Improves Neural Network TrainingChengyue Gong, Tongzheng Ren, Mao Ye, Qiang LiuCVPR 2021
- Adversarial Unlearning: Reducing Confidence Along Adversarial DirectionsAmrith Setlur, Benjamin Eysenbach, Virginia Smith, Sergey LevineNeurIPS 2022 · 被引用 26 次
- Jacobian Adversarially Regularized Networks for RobustnessAlvin Chan, Yi Tay, Yew-Soon Ong, Jie FuICLR 2020 · 被引用 81 次
- ε-weakened robustness of deep neural networksPei Huang, Yuting Yang, Minghao Liu, Fuqi Jia 等ISSTA 2022 · 被引用 10 次
- Splitting the Difference on Adversarial TrainingMatan Levi, Aryeh KontorovichUSENIX Security 2024 · 被引用 9 次
