Saved in:
Bibliographic Details
Main Authors: Wu, Yinting, Peng, Pai, Cai, Bo, Li, Le, .
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2406.04070
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909218443886592
author Wu, Yinting
Peng, Pai
Cai, Bo
Li, Le
.
author_facet Wu, Yinting
Peng, Pai
Cai, Bo
Li, Le
.
contents Adversarial training methods commonly generate independent initial perturbation for adversarial samples from a simple uniform distribution, and obtain the training batch for the classifier without selection. In this work, we propose a simple yet effective training framework called Batch-in-Batch (BB) to enhance models robustness. It involves specifically a joint construction of initial values that could simultaneously generates $m$ sets of perturbations from the original batch set to provide more diversity for adversarial samples; and also includes various sample selection strategies that enable the trained models to have smoother losses and avoid overconfident outputs. Through extensive experiments on three benchmark datasets (CIFAR-10, SVHN, CIFAR-100) with two networks (PreActResNet18 and WideResNet28-10) that are used in both the single-step (Noise-Fast Gradient Sign Method, N-FGSM) and multi-step (Projected Gradient Descent, PGD-10) adversarial training, we show that models trained within the BB framework consistently have higher adversarial accuracy across various adversarial settings, notably achieving over a 13% improvement on the SVHN dataset with an attack radius of 8/255 compared to the N-FGSM baseline model. Furthermore, experimental analysis of the efficiency of both the proposed initial perturbation method and sample selection strategies validates our insights. Finally, we show that our framework is cost-effective in terms of computational resources, even with a relatively large value of $m$.
format Preprint
id arxiv_https___arxiv_org_abs_2406_04070
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Batch-in-Batch: a new adversarial training framework for initial perturbation and sample selection
Wu, Yinting
Peng, Pai
Cai, Bo
Li, Le
.
Machine Learning
Artificial Intelligence
Adversarial training methods commonly generate independent initial perturbation for adversarial samples from a simple uniform distribution, and obtain the training batch for the classifier without selection. In this work, we propose a simple yet effective training framework called Batch-in-Batch (BB) to enhance models robustness. It involves specifically a joint construction of initial values that could simultaneously generates $m$ sets of perturbations from the original batch set to provide more diversity for adversarial samples; and also includes various sample selection strategies that enable the trained models to have smoother losses and avoid overconfident outputs. Through extensive experiments on three benchmark datasets (CIFAR-10, SVHN, CIFAR-100) with two networks (PreActResNet18 and WideResNet28-10) that are used in both the single-step (Noise-Fast Gradient Sign Method, N-FGSM) and multi-step (Projected Gradient Descent, PGD-10) adversarial training, we show that models trained within the BB framework consistently have higher adversarial accuracy across various adversarial settings, notably achieving over a 13% improvement on the SVHN dataset with an attack radius of 8/255 compared to the N-FGSM baseline model. Furthermore, experimental analysis of the efficiency of both the proposed initial perturbation method and sample selection strategies validates our insights. Finally, we show that our framework is cost-effective in terms of computational resources, even with a relatively large value of $m$.
title Batch-in-Batch: a new adversarial training framework for initial perturbation and sample selection
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2406.04070