Adversarial Training in Low-Label Regimes with Margin-Based Interpolation

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Ye, Tian, Kannan, Rajgopal, Prasanna, Viktor
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866909406379114496
author Ye, Tian
Kannan, Rajgopal
Prasanna, Viktor
author_facet Ye, Tian
Kannan, Rajgopal
Prasanna, Viktor
contents Adversarial training has emerged as an effective approach to train robust neural network models that are resistant to adversarial attacks, even in low-label regimes where labeled data is scarce. In this paper, we introduce a novel semi-supervised adversarial training approach that enhances both robustness and natural accuracy by generating effective adversarial examples. Our method begins by applying linear interpolation between clean and adversarial examples to create interpolated adversarial examples that cross decision boundaries by a controlled margin. This sample-aware strategy tailors adversarial examples to the characteristics of each data point, enabling the model to learn from the most informative perturbations. Additionally, we propose a global epsilon scheduling strategy that progressively adjusts the upper bound of perturbation strengths during training. The combination of these strategies allows the model to develop increasingly complex decision boundaries with better robustness and natural accuracy. Empirical evaluations show that our approach effectively enhances performance against various adversarial attacks, such as PGD and AutoAttack.
format Preprint
id arxiv_https___arxiv_org_abs_2411_17959
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Adversarial Training in Low-Label Regimes with Margin-Based Interpolation
Ye, Tian
Kannan, Rajgopal
Prasanna, Viktor
Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
Adversarial training has emerged as an effective approach to train robust neural network models that are resistant to adversarial attacks, even in low-label regimes where labeled data is scarce. In this paper, we introduce a novel semi-supervised adversarial training approach that enhances both robustness and natural accuracy by generating effective adversarial examples. Our method begins by applying linear interpolation between clean and adversarial examples to create interpolated adversarial examples that cross decision boundaries by a controlled margin. This sample-aware strategy tailors adversarial examples to the characteristics of each data point, enabling the model to learn from the most informative perturbations. Additionally, we propose a global epsilon scheduling strategy that progressively adjusts the upper bound of perturbation strengths during training. The combination of these strategies allows the model to develop increasingly complex decision boundaries with better robustness and natural accuracy. Empirical evaluations show that our approach effectively enhances performance against various adversarial attacks, such as PGD and AutoAttack.
title Adversarial Training in Low-Label Regimes with Margin-Based Interpolation
topic Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2411.17959