Towards Understanding Fast Adversarial Training

06/04/2020
by   Bai Li, et al.
17

Current neural-network-based classifiers are susceptible to adversarial examples. The most empirically successful approach to defending against such adversarial examples is adversarial training, which incorporates a strong self-attack during training to enhance its robustness. This approach, however, is computationally expensive and hence is hard to scale up. A recent work, called fast adversarial training, has shown that it is possible to markedly reduce computation time without sacrificing significant performance. This approach incorporates simple self-attacks, yet it can only run for a limited number of training epochs, resulting in sub-optimal performance. In this paper, we conduct experiments to understand the behavior of fast adversarial training and show the key to its success is the ability to recover from overfitting to weak attacks. We then extend our findings to improve fast adversarial training, demonstrating superior robust accuracy to strong adversarial training, with much-reduced training time.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/27/2019

Efficient Adversarial Training with Transferable Adversarial Examples

Adversarial training is an effective defense method to protect classific...
research
07/21/2022

Towards Efficient Adversarial Training on Vision Transformers

Vision Transformer (ViT), as a powerful alternative to Convolutional Neu...
research
07/01/2022

Efficient Adversarial Training With Data Pruning

Neural networks are susceptible to adversarial examples-small input pert...
research
07/08/2020

Fast Training of Deep Neural Networks Robust to Adversarial Perturbations

Deep neural networks are capable of training fast and generalizing well ...
research
02/24/2020

Fast and Stable Adversarial Training through Noise Injection

Adversarial training is the most successful empirical method, to increas...
research
05/08/2023

Toward Adversarial Training on Contextualized Language Representation

Beyond the success story of adversarial training (AT) in the recent text...
research
06/13/2020

ClustTR: Clustering Training for Robustness

This paper studies how encouraging semantically-aligned features during ...

Please sign up or login with your details

Forgot password? Click here to reset