Exploring Memorization in Adversarial Training
arXiv:2106.01606
Abstract
Deep learning models have a propensity for fitting the entire training set even with random labels, which requires memorization of every training sample. In this paper, we explore the memorization effect in adversarial training (AT) for promoting a deeper understanding of model capacity, convergence, generalization, and especially robust overfitting of the adversarially trained models. We first demonstrate that deep networks have sufficient capacity to memorize adversarial examples of training data with completely random labels, but not all AT algorithms can converge under the extreme circumstance. Our study of AT with random labels motivates further analyses on the convergence and generalization of AT. We find that some AT approaches suffer from a gradient instability issue and most recently suggested complexity measures cannot explain robust generalization by considering models trained on random labels. Furthermore, we identify a significant drawback of memorization in AT that it could result in robust overfitting. We then propose a new mitigation algorithm motivated by detailed memorization analyses. Extensive experiments on various datasets validate the effectiveness of the proposed method.
Accepted by ICLR 2022. 24 pages
References in corpus (10)
- Theoretically Principled Trade-off between Robustness and Accuracy
- Certified Adversarial Robustness via Randomized Smoothing
- Fast is better than free: Revisiting adversarial training
- A Closer Look at Memorization in Deep Networks
- Improving Adversarial Robustness via Promoting Ensemble Diversity
- On the Convergence and Robustness of Adversarial Training
- Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples
- Norm-Based Capacity Control in Neural Networks
- Metric Learning for Adversarial Robustness
- On the Loss Landscape of Adversarial Training: Identifying Challenges and How to Overcome Them