GReAT: A Graph Regularized Adversarial Training Method

被引:0
作者
Bayram, Samet [1 ]
Barner, Kenneth [1 ]
机构
[1] Univ Delaware, Elect & Comp Engn Dept, Newark, DE 19716 USA
关键词
Adversarial examples; adversarial learning; adversarial training; graph regularization; image classification; semi-supervised learning; robustness;
D O I
10.1109/ACCESS.2024.3395976
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents GReAT (Graph Regularized Adversarial Training), a novel regularization method designed to enhance the robust classification performance of deep learning models. Adversarial examples, characterized by subtle perturbations that can mislead models, pose a significant challenge in machine learning. Although adversarial training is effective in defending against such attacks, it often overlooks the underlying data structure. In response, GReAT integrates graph-based regularization into the adversarial training process, leveraging the data's inherent structure to enhance model robustness. By incorporating graph information during training, GReAT defends against adversarial attacks and improves generalization to unseen data. Extensive evaluations on benchmark datasets demonstrate that GReAT outperforms state-of-the-art methods in robustness, achieving notable improvements in classification accuracy. Specifically, compared to the second-best methods, GReAT achieves a performance increase of approximately 4.87% for CIFAR-10 against FGSM attack and 10.57% for SVHN against FGSM attack. Additionally, for CIFAR-10, GReAT demonstrates a performance increase of approximately 11.05% against PGD attack, and for SVHN, a 5.54% increase against PGD attack. This paper provides detailed insights into the proposed methodology, including numerical results and comparisons with existing approaches, highlighting the significant impact of GReAT in advancing the performance of deep learning models.
引用
收藏
页码:63130 / 63141
页数:12
相关论文
共 49 条
[11]   Towards Evaluating the Robustness of Neural Networks [J].
Carlini, Nicholas ;
Wagner, David .
2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, :39-57
[12]  
Carmon Y, 2019, 33 C NEURAL INFORM P, V32
[13]   Improving Adversarial Robustness via Guided Complement Entropy [J].
Chen, Hao-Yun ;
Liang, Jhao-Hong ;
Chang, Shih-Chieh ;
Pan, Jia-Yu ;
Chen, Yu-Ting ;
Wei, Wei ;
Juan, Da-Cheng .
2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, :4880-4888
[14]  
Eykholt K, 2018, Arxiv, DOI [arXiv:1707.08945, DOI 10.48550/ARXIV.1707.08945]
[15]  
Goodfellow I.J., 2015, 2015 INT C LEARN REP
[16]   Generative Adversarial Networks [J].
Goodfellow, Ian ;
Pouget-Abadie, Jean ;
Mirza, Mehdi ;
Xu, Bing ;
Warde-Farley, David ;
Ozair, Sherjil ;
Courville, Aaron ;
Bengio, Yoshua .
COMMUNICATIONS OF THE ACM, 2020, 63 (11) :139-144
[17]   Deep Residual Learning for Image Recognition [J].
He, Kaiming ;
Zhang, Xiangyu ;
Ren, Shaoqing ;
Sun, Jian .
2016 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2016, :770-778
[18]  
Huang G, 2018, Arxiv, DOI [arXiv:1608.06993, DOI 10.48550/ARXIV.1608.06993]
[19]   Learning Latent Representations of Nodes for Classifying in Heterogeneous Social Networks [J].
Jacob, Yann ;
Denoyer, Ludovic ;
Gallinari, Patrick .
WSDM'14: PROCEEDINGS OF THE 7TH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, 2014, :373-382
[20]  
Jiang ZY, 2020, Arxiv, DOI arXiv:2010.13337