Dynamic Label Adversarial Training for Deep Learning Robustness Against Adversarial Attacks

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Liu, Zhenyu, Duan, Haoran, Liang, Huizhi, Long, Yang, Snasel, Vaclav, Nicosia, Guiseppe, Ranjan, Rajiv, Ojha, Varun
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866914921537601536
author Liu, Zhenyu
Duan, Haoran
Liang, Huizhi
Long, Yang
Snasel, Vaclav
Nicosia, Guiseppe
Ranjan, Rajiv
Ojha, Varun
author_facet Liu, Zhenyu
Duan, Haoran
Liang, Huizhi
Long, Yang
Snasel, Vaclav
Nicosia, Guiseppe
Ranjan, Rajiv
Ojha, Varun
contents Adversarial training is one of the most effective methods for enhancing model robustness. Recent approaches incorporate adversarial distillation in adversarial training architectures. However, we notice two scenarios of defense methods that limit their performance: (1) Previous methods primarily use static ground truth for adversarial training, but this often causes robust overfitting; (2) The loss functions are either Mean Squared Error or KL-divergence leading to a sub-optimal performance on clean accuracy. To solve those problems, we propose a dynamic label adversarial training (DYNAT) algorithm that enables the target model to gradually and dynamically gain robustness from the guide model's decisions. Additionally, we found that a budgeted dimension of inner optimization for the target model may contribute to the trade-off between clean accuracy and robust accuracy. Therefore, we propose a novel inner optimization method to be incorporated into the adversarial training. This will enable the target model to adaptively search for adversarial examples based on dynamic labels from the guiding model, contributing to the robustness of the target model. Extensive experiments validate the superior performance of our approach.
format Preprint
id arxiv_https___arxiv_org_abs_2408_13102
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Dynamic Label Adversarial Training for Deep Learning Robustness Against Adversarial Attacks
Liu, Zhenyu
Duan, Haoran
Liang, Huizhi
Long, Yang
Snasel, Vaclav
Nicosia, Guiseppe
Ranjan, Rajiv
Ojha, Varun
Machine Learning
Computer Vision and Pattern Recognition
Adversarial training is one of the most effective methods for enhancing model robustness. Recent approaches incorporate adversarial distillation in adversarial training architectures. However, we notice two scenarios of defense methods that limit their performance: (1) Previous methods primarily use static ground truth for adversarial training, but this often causes robust overfitting; (2) The loss functions are either Mean Squared Error or KL-divergence leading to a sub-optimal performance on clean accuracy. To solve those problems, we propose a dynamic label adversarial training (DYNAT) algorithm that enables the target model to gradually and dynamically gain robustness from the guide model's decisions. Additionally, we found that a budgeted dimension of inner optimization for the target model may contribute to the trade-off between clean accuracy and robust accuracy. Therefore, we propose a novel inner optimization method to be incorporated into the adversarial training. This will enable the target model to adaptively search for adversarial examples based on dynamic labels from the guiding model, contributing to the robustness of the target model. Extensive experiments validate the superior performance of our approach.
title Dynamic Label Adversarial Training for Deep Learning Robustness Against Adversarial Attacks
topic Machine Learning
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2408.13102