Understanding Robust Overfitting of Adversarial Training and Beyond

by   Chaojian Yu, et al.

Robust overfitting widely exists in adversarial training of deep networks. The exact underlying reasons for this are still not completely understood. Here, we explore the causes of robust overfitting by comparing the data distribution of non-overfit (weak adversary) and overfitted (strong adversary) adversarial training, and observe that the distribution of the adversarial data generated by weak adversary mainly contain small-loss data. However, the adversarial data generated by strong adversary is more diversely distributed on the large-loss data and the small-loss data. Given these observations, we further designed data ablation adversarial training and identify that some small-loss data which are not worthy of the adversary strength cause robust overfitting in the strong adversary mode. To relieve this issue, we propose minimum loss constrained adversarial training (MLCAT): in a minibatch, we learn large-loss data as usual, and adopt additional measures to increase the loss of the small-loss data. Technically, MLCAT hinders data fitting when they become easy to learn to prevent robust overfitting; philosophically, MLCAT reflects the spirit of turning waste into treasure and making the best use of each adversarial data; algorithmically, we designed two realizations of MLCAT, and extensive experiments demonstrate that MLCAT can eliminate robust overfitting and further boost adversarial robustness.


page 1

page 2

page 3

page 4


Robust Weight Perturbation for Adversarial Training

Overfitting widely exists in adversarial robust training of deep network...

The Curious Case of Adversarially Robust Models: More Data Can Help, Double Descend, or Hurt Generalization

Despite remarkable success, deep neural networks are sensitive to human-...

Data Profiling for Adversarial Training: On the Ruin of Problematic Data

Multiple intriguing problems hover in adversarial training, including ro...

Strength-Adaptive Adversarial Training

Adversarial training (AT) is proved to reliably improve network's robust...

Exploring Memorization in Adversarial Training

It is well known that deep learning models have a propensity for fitting...

ROMark: A Robust Watermarking System Using Adversarial Training

The availability and easy access to digital communication increase the r...

Overfitting of neural nets under class imbalance: Analysis and improvements for segmentation

Overfitting in deep learning has been the focus of a number of recent wo...

Please sign up or login with your details

Forgot password? Click here to reset