AROID: Improving Adversarial Robustness through Online Instance-wise Data Augmentation

06/12/2023
by   Lin Li, et al.
0

Deep neural networks are vulnerable to adversarial examples. Adversarial training (AT) is an effective defense against adversarial examples. However, AT is prone to overfitting which degrades robustness substantially. Recently, data augmentation (DA) was shown to be effective in mitigating robust overfitting if appropriately designed and optimized for AT. This work proposes a new method to automatically learn online, instance-wise, DA policies to improve robust generalization for AT. A novel policy learning objective, consisting of Vulnerability, Affinity and Diversity, is proposed and shown to be sufficiently effective and efficient to be practical for automatic DA generation during AT. This allows our method to efficiently explore a large search space for a more effective DA policy and evolve the policy as training progresses. Empirically, our method is shown to outperform or match all competitive DA methods across various model architectures (CNNs and ViTs) and datasets (CIFAR10, SVHN and Imagenette). Our DA policy reinforced vanilla AT to surpass several state-of-the-art AT methods (with baseline DA) in terms of both accuracy and robustness. It can also be combined with those advanced AT methods to produce a further boost in robustness.

READ FULL TEXT

page 2

page 16

page 17

research
01/24/2023

Data Augmentation Alone Can Improve Adversarial Training

Adversarial training suffers from the issue of robust overfitting, which...
research
11/13/2022

Adversarial and Random Transformations for Robust Domain Adaptation and Generalization

Data augmentation has been widely used to improve generalization in trai...
research
05/25/2023

Visualizing data augmentation in deep speaker recognition

Visualization is of great value in understanding the internal mechanisms...
research
03/08/2021

Consistency Regularization for Adversarial Robustness

Adversarial training (AT) is currently one of the most successful method...
research
03/20/2021

Patch AutoAugment

Data augmentation (DA) plays a critical role in training deep neural net...
research
06/28/2021

Data augmentation for deep learning based accelerated MRI reconstruction with limited data

Deep neural networks have emerged as very successful tools for image res...
research
11/24/2021

Challenges of Adversarial Image Augmentations

Image augmentations applied during training are crucial for the generali...

Please sign up or login with your details

Forgot password? Click here to reset