Wasserstein distributional adversarial training for deep neural networks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Bai, Xingjian, He, Guangyi, Jiang, Yifan, Obloj, Jan
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866910825652944896
author Bai, Xingjian
He, Guangyi
Jiang, Yifan
Obloj, Jan
author_facet Bai, Xingjian
He, Guangyi
Jiang, Yifan
Obloj, Jan
contents Design of adversarial attacks for deep neural networks, as well as methods of adversarial training against them, are subject of intense research. In this paper, we propose methods to train against distributional attack threats, extending the TRADES method used for pointwise attacks. Our approach leverages recent contributions and relies on sensitivity analysis for Wasserstein distributionally robust optimization problems. We introduce an efficient fine-tuning method which can be deployed on a previously trained model. We test our methods on a range of pre-trained models on RobustBench. These experimental results demonstrate the additional training enhances Wasserstein distributional robustness, while maintaining original levels of pointwise robustness, even for already very successful networks. The improvements are less marked for models pre-trained using huge synthetic datasets of 20-100M images. However, remarkably, sometimes our methods are still able to improve their performance even when trained using only the original training dataset (50k images).
format Preprint
id arxiv_https___arxiv_org_abs_2502_09352
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Wasserstein distributional adversarial training for deep neural networks
Bai, Xingjian
He, Guangyi
Jiang, Yifan
Obloj, Jan
Machine Learning
Computer Vision and Pattern Recognition
Optimization and Control
Design of adversarial attacks for deep neural networks, as well as methods of adversarial training against them, are subject of intense research. In this paper, we propose methods to train against distributional attack threats, extending the TRADES method used for pointwise attacks. Our approach leverages recent contributions and relies on sensitivity analysis for Wasserstein distributionally robust optimization problems. We introduce an efficient fine-tuning method which can be deployed on a previously trained model. We test our methods on a range of pre-trained models on RobustBench. These experimental results demonstrate the additional training enhances Wasserstein distributional robustness, while maintaining original levels of pointwise robustness, even for already very successful networks. The improvements are less marked for models pre-trained using huge synthetic datasets of 20-100M images. However, remarkably, sometimes our methods are still able to improve their performance even when trained using only the original training dataset (50k images).
title Wasserstein distributional adversarial training for deep neural networks
topic Machine Learning
Computer Vision and Pattern Recognition
Optimization and Control
url https://arxiv.org/abs/2502.09352