Geometry-aware Instance-reweighted Adversarial Training
arXiv:2010.01736
Abstract
In adversarial machine learning, there was a common belief that robustness and accuracy hurt each other. The belief was challenged by recent studies where we can maintain the robustness and improve the accuracy. However, the other direction, whether we can keep the accuracy while improving the robustness, is conceptually and practically more interesting, since robust accuracy should be lower than standard accuracy for any model. In this paper, we show this direction is also promising. Firstly, we find even over-parameterized deep networks may still have insufficient model capacity, because adversarial training has an overwhelming smoothing effect. Secondly, given limited model capacity, we argue adversarial data should have unequal importance: geometrically speaking, a natural data point closer to/farther from the class boundary is less/more robust, and the corresponding adversarial data point should be assigned with larger/smaller weight. Finally, to implement the idea, we propose geometry-aware instance-reweighted adversarial training, where the weights are based on how difficult it is to attack a natural data point. Experiments show that our proposal boosts the robustness of standard adversarial training; combining two directions, we improve both robustness and accuracy of standard adversarial training.
ICLR 2021, Oral, Code <https://github.com/zjfheart/Geometry-aware-Instance-reweighted-Adversarial-Training>
References in corpus (12)
- Theoretically Principled Trade-off between Robustness and Accuracy
- Certified Adversarial Robustness via Randomized Smoothing
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
- Using Pre-Training Can Improve Model Robustness and Uncertainty
- Adversarial Robustness through Local Linearization
- On the Convergence and Robustness of Adversarial Training
- Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples
- MMA Training: Direct Input Space Margin Maximization through Adversarial Training
- Adversarial Robustness: From Self-Supervised Pre-Training to Fine-Tuning
- Once-for-All Adversarial Training: In-Situ Tradeoff between Robustness and Accuracy for Free
- Understanding the Interaction of Adversarial Training with Noisy Labels
- Guided Interpolation for Adversarial Training
Cited by in corpus (5)
- What You See is Not What the Network Infers: Detecting Adversarial Examples Based on Semantic Contradiction
- Sparse and Imperceptible Adversarial Attack via a Homotopy Algorithm
- Data Quality Matters For Adversarial Training: An Empirical Study
- Towards the Memorization Effect of Neural Networks in Adversarial Training
- Get Fooled for the Right Reason: Improving Adversarial Robustness through a Teacher-guided Curriculum Learning Approach