Boosting Adversarial Training with Hypersphere Embedding

02/20/2020
by   Tianyu Pang, et al.
13

Adversarial training (AT) is one of the most effective defenses to improve the adversarial robustness of deep learning models. In order to promote the reliability of the adversarially trained models, we propose to boost AT via incorporating hypersphere embedding (HE), which can regularize the adversarial features onto compact hypersphere manifolds. We formally demonstrate that AT and HE are well coupled, which tunes up the learning dynamics of AT from several aspects. We comprehensively validate the effectiveness and universality of HE by embedding it into the popular AT frameworks including PGD-AT, ALP, and TRADES, as well as the FreeAT and FastAT strategies. In experiments, we evaluate our methods on the CIFAR-10 and ImageNet datasets, and verify that integrating HE can consistently enhance the performance of the models trained by each AT framework with little extra computation.

READ FULL TEXT
research
10/13/2020

To be Robust or to be Fair: Towards Fairness in Adversarial Training

Adversarial training algorithms have been proven to be reliable to impro...
research
05/31/2021

Adversarial Training with Rectified Rejection

Adversarial training (AT) is one of the most effective strategies for pr...
research
07/28/2021

Imbalanced Adversarial Training with Reweighting

Adversarial training has been empirically proven to be one of the most e...
research
05/30/2020

Exploring Model Robustness with Adaptive Networks and Improved Adversarial Training

Adversarial training has proven to be effective in hardening networks ag...
research
08/23/2022

Predicting Query-Item Relationship using Adversarial Training and Robust Modeling Techniques

We present an effective way to predict search query-item relationship. W...
research
03/17/2022

On the Properties of Adversarially-Trained CNNs

Adversarial Training has proved to be an effective training paradigm to ...
research
09/15/2022

Explicit Tradeoffs between Adversarial and Natural Distributional Robustness

Several existing works study either adversarial or natural distributiona...

Please sign up or login with your details

Forgot password? Click here to reset