Defending Against Image Corruptions Through Adversarial Augmentations
arXiv:2104.01086
Abstract
Modern neural networks excel at image classification, yet they remain vulnerable to common image corruptions such as blur, speckle noise or fog. Recent methods that focus on this problem, such as AugMix and DeepAugment, introduce defenses that operate in expectation over a distribution of image corruptions. In contrast, the literature on -norm bounded perturbations focuses on defenses against worst-case corruptions. In this work, we reconcile both approaches by proposing AdversarialAugment, a technique which optimizes the parameters of image-to-image models to generate adversarially corrupted augmented images. We theoretically motivate our method and give sufficient conditions for the consistency of its idealized version as well as that of DeepAugment. Our classifiers improve upon the state-of-the-art on common image corruption benchmarks conducted in expectation on CIFAR-10-C and improve worst-case performance against -norm bounded perturbations on both CIFAR-10 and ImageNet.
References in corpus (22)
- Improved Regularization of Convolutional Neural Networks with Cutout
- Understanding deep learning requires rethinking generalization
- Theoretically Principled Trade-off between Robustness and Accuracy
- The Unreasonable Effectiveness of Deep Features as a Perceptual Metric
- AutoAugment: Learning Augmentation Policies from Data
- ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness
- Fast is better than free: Revisiting adversarial training
- Generalisation in humans and deep neural networks
- Do ImageNet Classifiers Generalize to ImageNet?
- Invariant Risk Minimization
- Lossy Image Compression with Compressive Autoencoders
- Generating Adversarial Examples with Adversarial Networks
- Adversarial Transformation Networks: Learning to Generate Adversarial Examples
- Adversarial Robustness through Local Linearization
- Natural Adversarial Examples
- Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples
- Adversarial Training Can Hurt Generalization
- RobustBench: a standardized adversarial robustness benchmark
- Improving Robustness Without Sacrificing Accuracy with Patch Gaussian Augmentation
- A Fourier Perspective on Model Robustness in Computer Vision
- Compounding the Performance Improvements of Assembled Techniques in a Convolutional Neural Network
- On the effectiveness of adversarial training against common corruptions