返回
AROID: Improving Adversarial Robustness Through Online Instance-Wise Data Augmentation
DOI:10.1007/s11263-024-02206-4.png)
摘要
En 中文
Deep neural networks are vulnerable to adversarial examples. Adversarial training (AT) is an effective defense against adversarial examples. However, AT is prone to overfitting which degrades robustness substantially. Recently, data augmentation (DA) was shown to be effective in mitigating robust overfitting if appropriately designed and optimized for AT. This work proposes a new method to automatically learn online, instance-wise, DA policies to improve robust generalization for AT. This is the first automated DA method specific for robustness. A novel policy learning objective, consisting of Vulnerability, Affinity and Diversity, is proposed and shown to be sufficiently effective and efficient to be practical for automatic DA generation during AT. Importantly, our method dramatically reduces the cost of policy search from the 5000 h of AutoAugment and the 412 h of IDBH to 9 h, making automated DA more practical to use for adversarial robustness. This allows our method to efficiently explore a large search space for a more effective DA policy and evolve the policy as training progresses. Empirically, our method is shown to outperform all competitive DA methods across various model architectures and datasets. Our DA policy reinforced vanilla AT to surpass several state-of-the-art AT methods regarding both accuracy and robustness. It can also be combined with those advanced AT methods to further boost robustness. Code and pre-trained models are available at: https://github.com/TreeLLi/AROID.
Keyword:
Adversarial robustness
Adversarial training
Data augmentation
Automated data augmentation
期刊
IF:
9.3
论文数:
3.9K
被引数:
2.8W
机构
引用论文
Welding characteristics of aluminum, copper, nickel and aluminum alloy with alumina coating using ultrasonic complex vibration welding equipments铝、铜、镍及铝合金氧化铝涂层超声复合振动焊接特性研究
Energy-Efficient Robot Configuration and Motion Planning Using Genetic Algorithm and Particle Swarm Optimization基于遗传算法和粒子群算法的节能机器人配置和运动规划
Energies
IF0
Do Perceptions of Competence Mediate The Relationship Between Fundamental Motor Skill Proficiency and Physical Activity Levels of Children in Kindergarten?能力的感知是否可以介导幼儿园儿童的基本运动技能熟练程度与身体活动水平之间的关系?
The Early Cambrian Mianyang-Changning Intracratonic Sag and Its Control on Petroleum Accumulation in the Sichuan Basin, China
Geofluids
IF0
Exploring misclassifications of robust neural networks to enhance adversarial attacks探索鲁棒神经网络的错误分类以增强对抗攻击
APPLIED INTELLIGENCE
IF3.5

