Return
Improving adversarial robustness by learning shared information
DOI:10.1016/j.patcog.2022.109054.png)
Abstract
En 中文
We consider the problem of improving the adversarial robustness of neural networks while retaining nat-ural accuracy. Motivated by the multi-view information bottleneck formalism, we seek to learn a repre-sentation that captures the shared information between clean samples and their corresponding adversar-ial samples while discarding these samples' view-specific information. We show that this approach leads to a novel multi-objective loss function, and we provide mathematical motivation for its components to-wards improving the robust vs. natural accuracy tradeoff. We demonstrate enhanced tradeoff compared to current state-of-the-art methods with extensive evaluation on various benchmark image datasets and architectures. Ablation studies indicate that learning shared representations is key to improving perfor-mance.(c) 2022 Elsevier Ltd. All rights reserved.
Keywords:
Adversarial robustness
Information bottleneck
Multi-view learning
Shared information
Journal
IF:
7.6
Papers:
1.3W
Citations:
4.5W


