Adversarial Training is a Form of Data-dependent Operator Norm Regularization
Kevin Roth, Yannic Kilcher, Thomas Hofmann
摘要
We establish a theoretical link between adversarial training and operator norm regularization for deep neural networks. Specifically, we prove that p-norm constrained projected gradient ascent based adversarial training with an q-norm loss on the logits of clean and perturbed inputs is equivalent to data-dependent (p, q) operator norm regularization. This fundamental connection confirms the long-standing argument that a network's sensitivity to adversarial examples is tied to its spectral properties and hints at novel ways to robustify and defend against adversarial attacks. We provide extensive empirical evidence on state-of-the-art network architectures to support our theoretical results.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper19
- LAS-AT: Adversarial Training with Learnable Attack StrategyXiaojun Jia, Yong Zhang, Baoyuan Wu, Ke Ma 等CVPR 2022 · 被引用 140 次
- An Exact Characterization of the Generalization Error for the Gibbs AlgorithmGholamali Aminian, Yuheng Bu, Laura Toni, Miguel R. D. Rodrigues 等NeurIPS 2021 · 被引用 75 次
- Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial TransferabilityYechao Zhang, Shengshan Hu, Leo Yu Zhang, Junyu Shi 等S&P 2024 · 被引用 36 次
- FEEL-SNN: Robust Spiking Neural Networks with Frequency Encoding and Evolutionary Leak FactorMengting Xu, De Ma, Huajin Tang, Qian Zheng 等NeurIPS 2024 · 被引用 23 次
- Enhancing the Robustness of Spiking Neural Networks with Stochastic Gating MechanismsJianhao Ding, Zhaofei Yu, Tiejun Huang, Jian K. LiuAAAI 2024 · 被引用 23 次
它引用的顶会 Paper1
相关 Paper
- Improving Adversarial Robustness by Putting More Regularizations on Less Robust SamplesDongyoon Yang, Insung Kong, Yongdai KimICML 2023 · 被引用 15 次
- Robust Design of Deep Neural Networks Against Adversarial Attacks Based on Lyapunov TheoryArash Rahnama, André T. Nguyen, Edward RaffCVPR 2020
- Large Norms of CNN Layers Do Not Hurt Adversarial RobustnessYouwei Liang, Dong HuangAAAI 2021 · 被引用 13 次
- PAC-Bayesian Spectrally-Normalized Bounds for Adversarially Robust GeneralizationJiancong Xiao, Ruoyu Sun, Zhi-Quan LuoNeurIPS 2023 · 被引用 14 次
- Intriguing Properties of Adversarial Training at ScaleCihang Xie, Alan L. YuilleICLR 2020 · 被引用 66 次
