Saved in:
Bibliographic Details
Main Authors: Wang, Ren, Li, Yuxuan, Hero, Alfred
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2407.09251
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917720907317248
author Wang, Ren
Li, Yuxuan
Hero, Alfred
author_facet Wang, Ren
Li, Yuxuan
Hero, Alfred
contents Deep learning models have shown considerable vulnerability to adversarial attacks, particularly as attacker strategies become more sophisticated. While traditional adversarial training (AT) techniques offer some resilience, they often focus on defending against a single type of attack, e.g., the $\ell_\infty$-norm attack, which can fail for other types. This paper introduces a computationally efficient multilevel $\ell_p$ defense, called the Efficient Robust Mode Connectivity (EMRC) method, which aims to enhance a deep learning model's resilience against multiple $\ell_p$-norm attacks. Similar to analytical continuation approaches used in continuous optimization, the method blends two $p$-specific adversarially optimal models, the $\ell_1$- and $\ell_\infty$-norm AT solutions, to provide good adversarial robustness for a range of $p$. We present experiments demonstrating that our approach performs better on various attacks as compared to AT-$\ell_\infty$, E-AT, and MSD, for datasets/architectures including: CIFAR-10, CIFAR-100 / PreResNet110, WideResNet, ViT-Base.
format Preprint
id arxiv_https___arxiv_org_abs_2407_09251
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Deep Adversarial Defense Against Multilevel-Lp Attacks
Wang, Ren
Li, Yuxuan
Hero, Alfred
Machine Learning
Artificial Intelligence
Signal Processing
Deep learning models have shown considerable vulnerability to adversarial attacks, particularly as attacker strategies become more sophisticated. While traditional adversarial training (AT) techniques offer some resilience, they often focus on defending against a single type of attack, e.g., the $\ell_\infty$-norm attack, which can fail for other types. This paper introduces a computationally efficient multilevel $\ell_p$ defense, called the Efficient Robust Mode Connectivity (EMRC) method, which aims to enhance a deep learning model's resilience against multiple $\ell_p$-norm attacks. Similar to analytical continuation approaches used in continuous optimization, the method blends two $p$-specific adversarially optimal models, the $\ell_1$- and $\ell_\infty$-norm AT solutions, to provide good adversarial robustness for a range of $p$. We present experiments demonstrating that our approach performs better on various attacks as compared to AT-$\ell_\infty$, E-AT, and MSD, for datasets/architectures including: CIFAR-10, CIFAR-100 / PreResNet110, WideResNet, ViT-Base.
title Deep Adversarial Defense Against Multilevel-Lp Attacks
topic Machine Learning
Artificial Intelligence
Signal Processing
url https://arxiv.org/abs/2407.09251