arrow
Return

Adversarial self-training for robustness and generalization

delete2024-09-01
delete2
PRE
AI
Z
Zhuorong Li *
吴明晖 cover
吴明晖 (Minghui Wu)
C
Canghong Jin
D
Daiwei Yu
H
Hongchuan Yu
DOI:10.1016/j.patrec.2024.07.020delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Adversarial training is currently one of the most promising ways to achieve adversarial robustness of deep models. However, even the most sophisticated training methods is far from satisfactory, as improvement in robustness requires either heuristic strategies or more annotated data, which might be problematic in real- world applications. To alleviate these issues, we propose an effective training scheme that avoids prohibitively high cost of additional labeled data by adapting self-training scheme to adversarial training. In particular, we first use the confident prediction for a randomly-augmented image as the pseudo-label for self-training. Then we enforce the consistency regularization by targeting the adversarially-perturbed version of the same image at the pseudo-label, which implicitly suppresses the distortion of representation in latent space. Despite its simplicity, extensive experiments show that our regularization could bring significant advancement in adversarial robustness of a wide range of adversarial training methods and helps the model to generalize its robustness to larger perturbations or even against unseen adversaries.
Keywords:
Adversarial defense
Adversarial attack
Robustness
Generalization
Self-training

Journal

Pattern Recognition Letters cover
Pattern Recognition Letters
IF:
3.3
Papers:
7.9K
Citations:
1.6W

Organization

B
Bournemouth University
Scholars:
2.7K
Papers: 3.0K
Citations: 3.5K
H
Hangzhou City University
Scholars:
2.2K
Papers: 2.0K
Citations: 1.0K