Topology-preserving Adversarial Training for Alleviating Natural Accuracy Degradation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mi, Xiaoyue, Tang, Fan, Weng, Yepeng, Wang, Danding, Cao, Juan, Tang, Sheng, Li, Peng, Liu, Yang
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914914480685056
author Mi, Xiaoyue
Tang, Fan
Weng, Yepeng
Wang, Danding
Cao, Juan
Tang, Sheng
Li, Peng
Liu, Yang
author_facet Mi, Xiaoyue
Tang, Fan
Weng, Yepeng
Wang, Danding
Cao, Juan
Tang, Sheng
Li, Peng
Liu, Yang
contents Despite the effectiveness in improving the robustness of neural networks, adversarial training has suffered from the natural accuracy degradation problem, i.e., accuracy on natural samples has reduced significantly. In this study, we reveal that natural accuracy degradation is highly related to the disruption of the natural sample topology in the representation space by quantitative and qualitative experiments. Based on this observation, we propose Topology-pReserving Adversarial traINing (TRAIN) to alleviate the problem by preserving the topology structure of natural samples from a standard model trained only on natural samples during adversarial training. As an additional regularization, our method can be combined with various popular adversarial training algorithms, taking advantage of both sides. Extensive experiments on CIFAR-10, CIFAR-100, and Tiny ImageNet show that our proposed method achieves consistent and significant improvements over various strong baselines in most cases. Specifically, without additional data, TRAIN achieves up to 8.86% improvement in natural accuracy and 6.33% improvement in robust accuracy.
format Preprint
id arxiv_https___arxiv_org_abs_2311_17607
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Topology-preserving Adversarial Training for Alleviating Natural Accuracy Degradation
Mi, Xiaoyue
Tang, Fan
Weng, Yepeng
Wang, Danding
Cao, Juan
Tang, Sheng
Li, Peng
Liu, Yang
Computer Vision and Pattern Recognition
Machine Learning
Despite the effectiveness in improving the robustness of neural networks, adversarial training has suffered from the natural accuracy degradation problem, i.e., accuracy on natural samples has reduced significantly. In this study, we reveal that natural accuracy degradation is highly related to the disruption of the natural sample topology in the representation space by quantitative and qualitative experiments. Based on this observation, we propose Topology-pReserving Adversarial traINing (TRAIN) to alleviate the problem by preserving the topology structure of natural samples from a standard model trained only on natural samples during adversarial training. As an additional regularization, our method can be combined with various popular adversarial training algorithms, taking advantage of both sides. Extensive experiments on CIFAR-10, CIFAR-100, and Tiny ImageNet show that our proposed method achieves consistent and significant improvements over various strong baselines in most cases. Specifically, without additional data, TRAIN achieves up to 8.86% improvement in natural accuracy and 6.33% improvement in robust accuracy.
title Topology-preserving Adversarial Training for Alleviating Natural Accuracy Degradation
topic Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2311.17607