Adversarial Training via Adaptive Knowledge Amalgamation of an Ensemble of Teachers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hamidi, Shayan Mohajer, Ye, Linfeng
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917672748318720
author Hamidi, Shayan Mohajer
Ye, Linfeng
author_facet Hamidi, Shayan Mohajer
Ye, Linfeng
contents Adversarial training (AT) is a popular method for training robust deep neural networks (DNNs) against adversarial attacks. Yet, AT suffers from two shortcomings: (i) the robustness of DNNs trained by AT is highly intertwined with the size of the DNNs, posing challenges in achieving robustness in smaller models; and (ii) the adversarial samples employed during the AT process exhibit poor generalization, leaving DNNs vulnerable to unforeseen attack types. To address these dual challenges, this paper introduces adversarial training via adaptive knowledge amalgamation of an ensemble of teachers (AT-AKA). In particular, we generate a diverse set of adversarial samples as the inputs to an ensemble of teachers; and then, we adaptively amalgamate the logtis of these teachers to train a generalized-robust student. Through comprehensive experiments, we illustrate the superior efficacy of AT-AKA over existing AT methods and adversarial robustness distillation techniques against cutting-edge attacks, including AutoAttack.
format Preprint
id arxiv_https___arxiv_org_abs_2405_13324
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Adversarial Training via Adaptive Knowledge Amalgamation of an Ensemble of Teachers
Hamidi, Shayan Mohajer
Ye, Linfeng
Machine Learning
Artificial Intelligence
Adversarial training (AT) is a popular method for training robust deep neural networks (DNNs) against adversarial attacks. Yet, AT suffers from two shortcomings: (i) the robustness of DNNs trained by AT is highly intertwined with the size of the DNNs, posing challenges in achieving robustness in smaller models; and (ii) the adversarial samples employed during the AT process exhibit poor generalization, leaving DNNs vulnerable to unforeseen attack types. To address these dual challenges, this paper introduces adversarial training via adaptive knowledge amalgamation of an ensemble of teachers (AT-AKA). In particular, we generate a diverse set of adversarial samples as the inputs to an ensemble of teachers; and then, we adaptively amalgamate the logtis of these teachers to train a generalized-robust student. Through comprehensive experiments, we illustrate the superior efficacy of AT-AKA over existing AT methods and adversarial robustness distillation techniques against cutting-edge attacks, including AutoAttack.
title Adversarial Training via Adaptive Knowledge Amalgamation of an Ensemble of Teachers
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2405.13324