Explaining the role of Intrinsic Dimensionality in Adversarial Training

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Altinisik, Enes, Messaoud, Safa, Sencar, Husrev Taha, Sajjad, Hassan, Chawla, Sanjay
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909622631137280
author Altinisik, Enes
Messaoud, Safa
Sencar, Husrev Taha
Sajjad, Hassan
Chawla, Sanjay
author_facet Altinisik, Enes
Messaoud, Safa
Sencar, Husrev Taha
Sajjad, Hassan
Chawla, Sanjay
contents Adversarial Training (AT) impacts different architectures in distinct ways: vision models gain robustness but face reduced generalization, encoder-based models exhibit limited robustness improvements with minimal generalization loss, and recent work in latent-space adversarial training (LAT) demonstrates that decoder-based models achieve improved robustness by applying AT across multiple layers. We provide the first explanation for these trends by leveraging the manifold conjecture: off-manifold adversarial examples (AEs) enhance robustness, while on-manifold AEs improve generalization. We show that vision and decoder-based models exhibit low intrinsic dimensionality in earlier layers (favoring off-manifold AEs), whereas encoder-based models do so in later layers (favoring on-manifold AEs). Exploiting this property, we introduce SMAAT, which improves the scalability of AT for encoder-based models by perturbing the layer with the lowest intrinsic dimensionality. This reduces the projected gradient descent (PGD) chain length required for AE generation, cutting GPU time by 25-33% while significantly boosting robustness. We validate SMAAT across multiple tasks, including text generation, sentiment classification, safety filtering, and retrieval augmented generation setups, demonstrating superior robustness with comparable generalization to standard training.
format Preprint
id arxiv_https___arxiv_org_abs_2405_17130
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Explaining the role of Intrinsic Dimensionality in Adversarial Training
Altinisik, Enes
Messaoud, Safa
Sencar, Husrev Taha
Sajjad, Hassan
Chawla, Sanjay
Machine Learning
Computation and Language
Adversarial Training (AT) impacts different architectures in distinct ways: vision models gain robustness but face reduced generalization, encoder-based models exhibit limited robustness improvements with minimal generalization loss, and recent work in latent-space adversarial training (LAT) demonstrates that decoder-based models achieve improved robustness by applying AT across multiple layers. We provide the first explanation for these trends by leveraging the manifold conjecture: off-manifold adversarial examples (AEs) enhance robustness, while on-manifold AEs improve generalization. We show that vision and decoder-based models exhibit low intrinsic dimensionality in earlier layers (favoring off-manifold AEs), whereas encoder-based models do so in later layers (favoring on-manifold AEs). Exploiting this property, we introduce SMAAT, which improves the scalability of AT for encoder-based models by perturbing the layer with the lowest intrinsic dimensionality. This reduces the projected gradient descent (PGD) chain length required for AE generation, cutting GPU time by 25-33% while significantly boosting robustness. We validate SMAAT across multiple tasks, including text generation, sentiment classification, safety filtering, and retrieval augmented generation setups, demonstrating superior robustness with comparable generalization to standard training.
title Explaining the role of Intrinsic Dimensionality in Adversarial Training
topic Machine Learning
Computation and Language
url https://arxiv.org/abs/2405.17130