arrow
返回

Boosting Fast Adversarial Training With Learnable Adversarial Initialization

delete2022-01-01
delete40
delete
OA
AI
X
Xiaojun Jia
Y
Yong Zhang *
B
Baoyuan Wu
J
Jue Wang
X
Xiaochun Cao *
DOI:10.1109/TIP.2022.3184255delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Adversarial training (AT) has been demonstrated to be effective in improving model robustness by leveraging adversarial examples for training. However, most AT methods are in face of expensive time and computational cost for calculating gradients at multiple steps in generating adversarial examples. To boost training efficiency, fast gradient sign method (FGSM) is adopted in fast AT methods by calculating gradient only once. Unfortunately, the robustness is far from satisfactory. One reason may arise from the initialization fashion. Existing fast AT generally uses a random sample-agnostic initialization, which facilitates the efficiency yet hinders a further robustness improvement. Up to now, the initialization in fast AT is still not extensively explored. In this paper, focusing on image classification, we boost fast AT with a sample-dependent adversarial initialization, i.e., an output from a generative network conditioned on a benign image and its gradient information from the target network. As the generative network and the target network are optimized jointly in the training phase, the former can adaptively generate an effective initialization with respect to the latter, which motivates gradually improved robustness. Experimental evaluations on four benchmark databases demonstrate the superiority of our proposed method over state-of-the-art fast AT methods, as well as comparable robustness to advanced multi-step AT methods. The code is released at https://github.com//jiaxiaojunQAQ//FGSM-SDI.
Keyword:
Robustness
Training
Perturbation methods
Computational efficiency
Neural networks
Minimization
Measurement
Fast adversarial training
sample-dependent initialization
generative network
gradient information

期刊

IEEE Transactions on Image Processing 封面图
IEEE Transactions on Image Processing
IF:
13.7
论文数:
1.0W
被引数:
8.4W

机构

U
university of chinese academy of sciences, cas
学者数:
4.1W
论文数: 3.8W
被引数: 75
T
The Chinese University of Hong Kong, Shenzhen
学者数:
4.3K
论文数: 4.0K
被引数: 7
C
chinese academy of sciences
学者数:
56.7W
论文数: 45.0W
被引数: 704
学者 查看更多机构
引用论文

引用论文

err
IF0
err
err0
PREAI
err
err分享
err收藏
Adversarial Attack Against Deep Saliency Models Powered by Non-Redundant Priors
err2021-01-01
err17
PREAI
errChe, Zhaohui; Borji, Ali; Zhai, Guangtao; Ling, Suiyi; Li, Jing; Tian, Yuan; Guo, Guodong; Le Callet, Patrick
err分享
err收藏
When Does Model-Based Control Pay Off?
err2016-08-26
err0
errOAAI
errWouter Kool; Fiery A. Cushman; Samuel J. Gershman
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容