Adversarial Robustness vs. Model Compression, or Both?
Shaokai Ye, Xue Lin, Kaidi Xu, Sijia Liu, Hao Cheng, Jan-Henrik Lambrechts, Huan Zhang, Aojun Zhou, Kaisheng Ma, Yanzhi Wang
摘要
It is well known that deep neural networks (DNNs) are vulnerable to adversarial attacks, which are implemented by adding crafted perturbations onto benign examples. Min-max robust optimization based adversarial training can provide a notion of security against adversarial attacks. However, adversarial robustness requires a significantly larger capacity of the network than that for the natural training with only benign examples. This paper proposes a framework of concurrent adversarial training and weight pruning that enables model compression while still preserving the adversarial robustness and essentially tackles the dilemma of adversarial training. Furthermore, this work studies two hypotheses about weight pruning in the conventional setting and finds that weight pruning is essential for reducing the network model size in the adversarial setting; training a small model from scratch even with inherited initialization from the large model cannot achieve neither adversarial robustness nor high standard accuracy. Code is available at https://github.com/yeshaokai/ Robustness-Aware-Pruning-ADMM .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper38
- HYDRA: Pruning Adversarially Robust Neural NetworksVikash Sehwag, Shiqi Wang, Prateek Mittal, Suman JanaNeurIPS 2020 · 被引用 242 次
- Towards Robust Vision TransformerXiaofeng Mao, Gege Qi, Yuefeng Chen, Xiaodan Li 等CVPR 2022 · 被引用 185 次
- The Unreasonable Effectiveness of Random Pruning: Return of the Most Naive Baseline for Sparse TrainingShiwei Liu, Tianlong Chen, Xiaohan Chen, Li Shen 等ICLR 2022 · 被引用 141 次
- On the Loss Landscape of Adversarial Training: Identifying Challenges and How to Overcome ThemChen Liu, Mathieu Salzmann, Tao Lin, Ryota Tomioka 等NeurIPS 2020 · 被引用 103 次
- Once-for-All Adversarial Training: In-Situ Tradeoff between Robustness and Accuracy for FreeHaotao Wang, Tianlong Chen, Shupeng Gui, Ting-Kuei Hu 等NeurIPS 2020 · 被引用 94 次
相关 Paper
- Masking Adversarial Damage: Finding Adversarial Saliency for Robust and Sparse NetworkByung-Kwan Lee, Junho Kim, Yong Man RoCVPR 2022 · 被引用 8 次
- CSTAR: Towards Compact and Structured Deep Neural Networks with Adversarial RobustnessHuy Phan, Miao Yin, Yang Sui, Bo Yuan 等AAAI 2023 · 被引用 10 次
- Learning Adversarially Robust Sparse Networks via Weight ReparameterizationChenhao Li, Qiang Qiu, Zhibin Zhang, Jiafeng Guo 等AAAI 2023 · 被引用 8 次
- A Unified DNN Weight Pruning Framework Using Reweighted Optimization MethodsTianyun Zhang, Xiaolong Ma, Zheng Zhan, Shanglin Zhou 等DAC 2021 · 被引用 25 次
- Adversarial Neural Pruning with Latent Vulnerability SuppressionDivyam Madaan, Jinwoo Shin, Sung Ju HwangICML 2020 · 被引用 68 次
