arrow
Return

Improving adversarial robustness by learning shared information

delete2023-02-01
delete13
PRE
AI
X
Xi Yu
N
Niklas Smedemark-Margulies
T
Toshiaki Koike‐Akino
P
Pierre Moulin
M
Matthew Brand
K
Kieran Parsons
Y
Ye Wang *
DOI:10.1016/j.patcog.2022.109054delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
We consider the problem of improving the adversarial robustness of neural networks while retaining nat-ural accuracy. Motivated by the multi-view information bottleneck formalism, we seek to learn a repre-sentation that captures the shared information between clean samples and their corresponding adversar-ial samples while discarding these samples' view-specific information. We show that this approach leads to a novel multi-objective loss function, and we provide mathematical motivation for its components to-wards improving the robust vs. natural accuracy tradeoff. We demonstrate enhanced tradeoff compared to current state-of-the-art methods with extensive evaluation on various benchmark image datasets and architectures. Ablation studies indicate that learning shared representations is key to improving perfor-mance.(c) 2022 Elsevier Ltd. All rights reserved.
Keywords:
Adversarial robustness
Information bottleneck
Multi-view learning
Shared information

Journal

Pattern Recognition cover
Pattern Recognition
IF:
7.6
Papers:
1.3W
Citations:
4.5W

Organization

U
University of Florida
Scholars:
4.0W
Papers: 3.1W
Citations: 6.6W
State University System of Florida cover
State University System of Florida
Scholars:
12.7W
Papers: 10.9W
Citations: 130
T
tufts university
Scholars:
1.7W
Papers: 1.5W
Citations: 24
N
Northeastern University
Scholars:
2.4W
Papers: 1.5W
Citations: 3.0W
University of Illinois System cover
University of Illinois System
Scholars:
6.8W
Papers: 6.2W
Citations: 644
researcher View more organizations