Inducing Data Amplification Using Auxiliary Datasets in Adversarial Training

09/27/2022
by   Saehyung Lee, et al.
0

Several recent studies have shown that the use of extra in-distribution data can lead to a high level of adversarial robustness. However, there is no guarantee that it will always be possible to obtain sufficient extra data for a selected dataset. In this paper, we propose a biased multi-domain adversarial training (BiaMAT) method that induces training data amplification on a primary dataset using publicly available auxiliary datasets, without requiring the class distribution match between the primary and auxiliary datasets. The proposed method can achieve increased adversarial robustness on a primary dataset by leveraging auxiliary datasets via multi-domain learning. Specifically, data amplification on both robust and non-robust features can be accomplished through the application of BiaMAT as demonstrated through a theoretical and empirical analysis. Moreover, we demonstrate that while existing methods are vulnerable to negative transfer due to the distributional discrepancy between auxiliary and primary data, the proposed method enables neural networks to flexibly leverage diverse image datasets for adversarial training by successfully handling the domain discrepancy through the application of a confidence-based selection strategy. The pre-trained models and code are available at: <https://github.com/Saehyung-Lee/BiaMAT>.

READ FULL TEXT
research
03/27/2023

CAT:Collaborative Adversarial Training

Adversarial training can improve the robustness of neural networks. Prev...
research
06/14/2018

Neural Stethoscopes: Unifying Analytic, Auxiliary and Adversarial Network Probing

Model interpretability and systematic, targeted model adaptation present...
research
10/27/2022

Efficient and Effective Augmentation Strategy for Adversarial Training

Adversarial training of Deep Neural Networks is known to be significantl...
research
09/10/2023

Outlier Robust Adversarial Training

Supervised learning models are challenged by the intrinsic complexities ...
research
09/26/2021

Generalized multiscale feature extraction for remaining useful life prediction of bearings with generative adversarial networks

Bearing is a key component in industrial machinery and its failure may l...
research
09/15/2022

Explicit Tradeoffs between Adversarial and Natural Distributional Robustness

Several existing works study either adversarial or natural distributiona...
research
06/09/2020

Adversarial Infidelity Learning for Model Interpretation

Model interpretation is essential in data mining and knowledge discovery...

Please sign up or login with your details

Forgot password? Click here to reset