Explaining the role of Intrinsic Dimensionality in Adversarial Training
Enes Altinisik, Safa Messaoud, Husrev Taha Sencar, Hassan Sajjad, Sanjay Chawla
摘要
Adversarial Training (AT) impacts different architectures in distinct ways: vision models gain robustness but face reduced generalization, encoderbased models exhibit limited robustness improvements with minimal generalization loss, and recent work in latent-space adversarial training (LAT) demonstrates that decoder-based models achieve improved robustness by applying AT across multiple layers. We provide the first explanation for these trends by leveraging the manifold conjecture: off-manifold adversarial examples (AEs) enhance robustness, while on-manifold AEs improve generalization. We show that vision and decoder-based models exhibit low intrinsic dimensionality in earlier layers (favoring offmanifold AEs), whereas encoder-based models do so in later layers (favoring on-manifold AEs). Exploiting this property, we introduce SMAAT, which improves the scalability of AT for encoderbased models by perturbing the layer with the lowest intrinsic dimensionality. This reduces the projected gradient descent (PGD) chain length required for AE generation, cutting GPU time by 25-33% while significantly boosting robustness. We validate SMAAT across multiple tasks, including text generation, sentiment classification, safety filtering, and retrieval augmented generation setups, demonstrating superior robustness with comparable generalization to standard training.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper17
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Training data-efficient image transformers & distillation through attentionHugo Touvron, Matthieu Cord, Matthijs Douze, Francisco Massa 等ICML 2021 · 被引用 8,974 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
- Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and EntailmentDi Jin, Zhijing Jin, Joey Tianyi Zhou, Peter SzolovitsAAAI 2020 · 被引用 1,333 次
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 被引用 1,295 次
相关 Paper
- Dual Manifold Adversarial Robustness: Defense against Lp and non-Lp Adversarial AttacksWei-An Lin, Chun Pong Lau, Alexander Levine, Rama Chellappa 等NeurIPS 2020 · 被引用 70 次
- Enhancing the Adversarial Robustness via Manifold ProjectionZhiting Li, Shibai Yin, Tai-Xiang Jiang, Yexun Hu 等AAAI 2025 · 被引用 5 次
- Semi-supervised Semantics-guided Adversarial Training for Robust Trajectory PredictionRuochen Jiao, Xiangguo Liu, Takami Sato, Qi Alfred Chen 等ICCV 2023 · 被引用 26 次
- Which Models have Perceptually-Aligned Gradients? An Explanation via Off-Manifold RobustnessSuraj Srinivas, Sebastian Bordt, Himabindu LakkarajuNeurIPS 2023 · 被引用 24 次
- Towards Compositional Adversarial Robustness: Generalizing Adversarial Training to Composite Semantic PerturbationsLei Hsiung, Yun-Yun Tsai, Pin-Yu Chen, Tsung-Yi HoCVPR 2023
